SlideShare una empresa de Scribd logo
1 de 30
Privacy and the Car of the
          Future
Consideration for the coming connected vehicle
whoami
•   BSEE, digital communications

•   Many years as a network engineer

•   Santa Clara University Law student

•   Research assistant providing technical expertise on privacy
    audits and reviews

•   Contracted by auto consortium to review privacy of
    proposed vehicle to vehicle safety network
Standard Disclaimer


                IANAL (Yet)
But if you know anyone looking for summer interns....
Non-Standard Disclaimer


A current NDA covers some of my work here (but not very
                           much)
 The focus will be on published information and standards.
What is This Project?

• DSRC: Dedicated Short Range Communications
    •   (Where “short” == 380m)

•   Vehicle to Vehicle

•   Vehicle to infrastructure in Europe
    - Not having to wait for a light on an empty street again.
    - Better traffic planning for better cities and roadways.
Why is It being Developed?



                                        Safety


Photo Credit: Jason Edward Scott Bain
Non-trivial Impact on Auto
                  Deaths
•   World Health Organization
    estimates 25% of vehicle
    deaths each year can be
    prevented.

•   Fatigue and distracted driving
    accidents reduced.

•   Blind Corners, fog and
    limited visibility accidents
    reduced.
                                     Photo: Public Domain
Will This really Happen?




    IT ALREADY IS
How Soon?
•   Hardware is already being shipped.

•   Software issues still entirely in the air

    •   More is being done in software these days.

•   The US Dept. of Transportation is considering mandating
    this for all new cars. (Decision to come later this year.)

•   Has already deployed in trucks in Europe
What is DSRC
•   Basic safety messages sent out
    every 1/10 seconds.

•   All message carry a standard
    glob: values for pre-defined
    vehicle trajectory and
    operational data.

•   Cars process data and warn
    driver.

•   Equipment integrated into
    vehicle                          Photo Credit: US Dept. of Transportation
Photo Credit: NIST




AfterMarket Installation
      A little cumbersome
What DSRC is not
                                           •   CANbus

                                           •   OnStar (or any other
                                               remote service)

                                           •   (Direct) support for
                                               autonomous driving
                                               mechanisms.

Photo Credit: US Dept. of Transportation
Technical details
Radio protocol
•   5.9GHz reserved in US and Europe
•   Signaling standard: IEEE 802.11p /
    1609.4 / 1609.3
•   Channels reserved for specific
    functions
•   No source address for vehicles
    defined by protocol
    •   Recommendations include using
        certificates
    •   Privacy challenges at each layer   Photo Credit: NASA
Basic Safety Message



•   Standard: SAE J2735

•   ~50 fixed data elements

•   “only” interface to radio
    (on this band)
Parameters for effectiveness
•   Density

    •   Benefit derived from other vehicles’ use

    •   Greater usage means greater effectiveness

•   Confidence

    •   Most messages must be trustworthy

    •   People must trust information broadcast
Validity?
•   All messages are
    cryptographically signed

•   Signing certificates issued by
    central authority

•   Issued based on system
    fingerprint

•   Revocation for “malfunctioning”      Image source: US Dept. of Transportation
    equipment

•   System should invalidate itself if
    internal checks fail
Certificates
•   Limited time use to prevent tracking

    •   Reused?

•   Periodically refreshed (and malefactors reported)

    •   How often?

•   Permanent blacklist
Privacy?
MAC Layer

•   Changeable source (for vehicles) / no destination

•   Unrouteable! (mostly)

•   No significant privacy concern as is.

•   Any algorithm to make network routeable will make
    vehicles trackable.
BSM



•   “Temporary” ID could become persistent with bad app

•   Open source apps suggested for processing and acting on
    message data

•   Is this the only thing the unit will transmit?
Certificates


•   Identity/Validity conflict

    •   Solution: constantly changing certificates

    •   Revocation by fingerprint

•   Issuing authority?
Fingerprints


•   “No” correspondence
    between fingerprint and car

•   “hard coded” into device

•   If revoked, entire unit must
    be replaced to function


                                   Photo Credit: NIST
Certificate Delivery

         •   Haven’t figured out how
             certificates are delivered to
             vehicle

         •   Proposals include cellular,
             wifi, infrastructure links

         •   So many opportunities for
             failure
Worrisome Noise



•   Manufacturers want to use this system for commercial apps

•   Advertising and other “funding” schemes to pay for CA

•   Fixed infrastructure potentially operated by data brokers
Problem: Law
    Enforcement

•   What can they do with this?

•   Correlate location, speed to
    independent identification?
    (cameras?)

                                   Photo Credit: Alex E. Proimos
What you Can Do
•   Hack the radios
    •   Commercially available now

•   Hack the protocols

•   Become politically engaged

    •   Most decisions are not being made by elected officials

    •   Help find a way to fund the infrastructure without selling
        out!
Thank you
Acknowledgements


•   Professor Dorothy Glancy, who requested my help on this
    project

•   DC 650 (especially Charles Blas) who gave me a reality
    check with current security and privacy capabilities
Contact

•   Christie Dudley

•   @longobord

•   c.dudley@ieee.org

Más contenido relacionado

La actualidad más candente

Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Symphony Teleca - The Connected Car Revolution @ Cebit 2014Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Symphony Teleca - The Connected Car Revolution @ Cebit 2014Peter Decker
 
Future mobile networks connected and autonomous cars
Future mobile networks  connected and autonomous carsFuture mobile networks  connected and autonomous cars
Future mobile networks connected and autonomous carslammya aa
 
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...Forth
 
IoT for V2V and Connected Car - AW Megatrends `14 panel
IoT for V2V and Connected Car - AW Megatrends `14 panelIoT for V2V and Connected Car - AW Megatrends `14 panel
IoT for V2V and Connected Car - AW Megatrends `14 panelJoe Speed
 
2015 Florida Automated Vehicles Initiative - FDOT - FTA
2015 Florida Automated Vehicles Initiative - FDOT - FTA2015 Florida Automated Vehicles Initiative - FDOT - FTA
2015 Florida Automated Vehicles Initiative - FDOT - FTAFlorida Trucking Association
 
2017 Autonomous Vehicle Presentation Package
2017 Autonomous Vehicle Presentation Package 2017 Autonomous Vehicle Presentation Package
2017 Autonomous Vehicle Presentation Package Michael Scheno
 
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan PetitAutomotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan PetitSecurity Innovation
 
The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19Mark Goldstein
 
Automotive Exploitation Techniques by Craig Smith
Automotive Exploitation Techniques by Craig SmithAutomotive Exploitation Techniques by Craig Smith
Automotive Exploitation Techniques by Craig SmithShakacon
 
Connected Car Investment Thesis
Connected Car Investment ThesisConnected Car Investment Thesis
Connected Car Investment ThesisJames Harris
 
The Autonomous Revolution of Vehicles and Transportation
The Autonomous Revolution  of Vehicles and TransportationThe Autonomous Revolution  of Vehicles and Transportation
The Autonomous Revolution of Vehicles and TransportationMark Goldstein
 
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris ValasekSuns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris ValasekShakacon
 
Addressing Security in the Automotive Industry
Addressing Security in the Automotive IndustryAddressing Security in the Automotive Industry
Addressing Security in the Automotive IndustrySasken Technologies Ltd.
 
Connected Cars - Poster Child for the IoT Reality Check
Connected Cars - Poster Child for the IoT Reality CheckConnected Cars - Poster Child for the IoT Reality Check
Connected Cars - Poster Child for the IoT Reality CheckSecurity Innovation
 
Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning  Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning  Junli Gu
 

La actualidad más candente (20)

The Connected Car: Impact on Wireless Communication
The Connected Car: Impact on Wireless CommunicationThe Connected Car: Impact on Wireless Communication
The Connected Car: Impact on Wireless Communication
 
Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Symphony Teleca - The Connected Car Revolution @ Cebit 2014Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Symphony Teleca - The Connected Car Revolution @ Cebit 2014
 
Future mobile networks connected and autonomous cars
Future mobile networks  connected and autonomous carsFuture mobile networks  connected and autonomous cars
Future mobile networks connected and autonomous cars
 
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
 
IoT for V2V and Connected Car - AW Megatrends `14 panel
IoT for V2V and Connected Car - AW Megatrends `14 panelIoT for V2V and Connected Car - AW Megatrends `14 panel
IoT for V2V and Connected Car - AW Megatrends `14 panel
 
Developing for the Connected Car
Developing for the Connected CarDeveloping for the Connected Car
Developing for the Connected Car
 
2015 Florida Automated Vehicles Initiative - FDOT - FTA
2015 Florida Automated Vehicles Initiative - FDOT - FTA2015 Florida Automated Vehicles Initiative - FDOT - FTA
2015 Florida Automated Vehicles Initiative - FDOT - FTA
 
2017 Autonomous Vehicle Presentation Package
2017 Autonomous Vehicle Presentation Package 2017 Autonomous Vehicle Presentation Package
2017 Autonomous Vehicle Presentation Package
 
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan PetitAutomotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
 
Connected and Autonomous Vehicle Systems R&D Overview
Connected and Autonomous Vehicle Systems R&D OverviewConnected and Autonomous Vehicle Systems R&D Overview
Connected and Autonomous Vehicle Systems R&D Overview
 
Connected and Automated Vehicles: Where Are We Going and What Happens When We...
Connected and Automated Vehicles: Where Are We Going and What Happens When We...Connected and Automated Vehicles: Where Are We Going and What Happens When We...
Connected and Automated Vehicles: Where Are We Going and What Happens When We...
 
The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19
 
Automotive Exploitation Techniques by Craig Smith
Automotive Exploitation Techniques by Craig SmithAutomotive Exploitation Techniques by Craig Smith
Automotive Exploitation Techniques by Craig Smith
 
Connected Car Investment Thesis
Connected Car Investment ThesisConnected Car Investment Thesis
Connected Car Investment Thesis
 
The Autonomous Revolution of Vehicles and Transportation
The Autonomous Revolution  of Vehicles and TransportationThe Autonomous Revolution  of Vehicles and Transportation
The Autonomous Revolution of Vehicles and Transportation
 
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris ValasekSuns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
 
Addressing Security in the Automotive Industry
Addressing Security in the Automotive IndustryAddressing Security in the Automotive Industry
Addressing Security in the Automotive Industry
 
Connected Cars - Poster Child for the IoT Reality Check
Connected Cars - Poster Child for the IoT Reality CheckConnected Cars - Poster Child for the IoT Reality Check
Connected Cars - Poster Child for the IoT Reality Check
 
Connecting California from Research to Reality
Connecting California from Research to RealityConnecting California from Research to Reality
Connecting California from Research to Reality
 
Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning  Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning 
 

Destacado

Intelligent transportation systems
Intelligent transportation systemsIntelligent transportation systems
Intelligent transportation systemsEngin Karabulut
 
The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec Winterwind
 
Black ice technologies rdas (finance)
Black ice technologies rdas (finance)Black ice technologies rdas (finance)
Black ice technologies rdas (finance)phillyjevs
 
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEMICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEMEdgeLab
 
FASTRInfographic2017
FASTRInfographic2017FASTRInfographic2017
FASTRInfographic2017Craig Hurst
 
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...Thomas Bamonte
 
Vestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, VestasVestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, VestasWinterwind
 
Braking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle VulnerabilitiesBraking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle VulnerabilitiesPriyanka Aash
 
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015Jukka Sassi
 
Electronic Toll Collection Global Study
Electronic Toll Collection Global StudyElectronic Toll Collection Global Study
Electronic Toll Collection Global StudyJustin Hamilton
 
Comparing CoAP vs MQTT
Comparing CoAP vs MQTTComparing CoAP vs MQTT
Comparing CoAP vs MQTTkellogh
 
Real Time Object Tracking
Real Time Object TrackingReal Time Object Tracking
Real Time Object TrackingVanya Valindria
 
Moving object detection
Moving object detectionMoving object detection
Moving object detectionManav Mittal
 
Electronic Toll Collection System
Electronic Toll Collection SystemElectronic Toll Collection System
Electronic Toll Collection SystemArshad Shareef
 
Internet of Things (IoT) protocols COAP MQTT OSCON2014
Internet of Things (IoT) protocols  COAP MQTT OSCON2014Internet of Things (IoT) protocols  COAP MQTT OSCON2014
Internet of Things (IoT) protocols COAP MQTT OSCON2014Vidhya Gholkar
 
Intelligent Transportation System (ITS)
Intelligent Transportation System (ITS)Intelligent Transportation System (ITS)
Intelligent Transportation System (ITS)Jonathan D'Cruz
 

Destacado (20)

Intelligent transportation systems
Intelligent transportation systemsIntelligent transportation systems
Intelligent transportation systems
 
The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec
 
Black ice technologies rdas (finance)
Black ice technologies rdas (finance)Black ice technologies rdas (finance)
Black ice technologies rdas (finance)
 
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEMICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
 
Sliding around on an icy road
Sliding around on an icy roadSliding around on an icy road
Sliding around on an icy road
 
Intevencion de espacial
Intevencion de espacialIntevencion de espacial
Intevencion de espacial
 
FASTRInfographic2017
FASTRInfographic2017FASTRInfographic2017
FASTRInfographic2017
 
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
 
Vestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, VestasVestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, Vestas
 
Braking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle VulnerabilitiesBraking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle Vulnerabilities
 
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
 
Electronic Toll Collection Global Study
Electronic Toll Collection Global StudyElectronic Toll Collection Global Study
Electronic Toll Collection Global Study
 
Comparing CoAP vs MQTT
Comparing CoAP vs MQTTComparing CoAP vs MQTT
Comparing CoAP vs MQTT
 
Real Time Object Tracking
Real Time Object TrackingReal Time Object Tracking
Real Time Object Tracking
 
Object tracking
Object trackingObject tracking
Object tracking
 
Moving object detection
Moving object detectionMoving object detection
Moving object detection
 
Electronic Toll Collection System
Electronic Toll Collection SystemElectronic Toll Collection System
Electronic Toll Collection System
 
The Connected Vehicle Movement
The Connected Vehicle MovementThe Connected Vehicle Movement
The Connected Vehicle Movement
 
Internet of Things (IoT) protocols COAP MQTT OSCON2014
Internet of Things (IoT) protocols  COAP MQTT OSCON2014Internet of Things (IoT) protocols  COAP MQTT OSCON2014
Internet of Things (IoT) protocols COAP MQTT OSCON2014
 
Intelligent Transportation System (ITS)
Intelligent Transportation System (ITS)Intelligent Transportation System (ITS)
Intelligent Transportation System (ITS)
 

Similar a Connected vehicles

Will Your Car Betray you
Will Your Car Betray youWill Your Car Betray you
Will Your Car Betray youChristie Dudley
 
Internet: Its Past, Present and The Future
Internet: Its Past, Present and The FutureInternet: Its Past, Present and The Future
Internet: Its Past, Present and The FutureAbhishek Tonpe
 
Mobile application testing
Mobile application testingMobile application testing
Mobile application testingSoftheme
 
The Cloud and the Car
The Cloud and the CarThe Cloud and the Car
The Cloud and the CarBarry Gander
 
Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010Iddan Halevy
 
How to Design Distributed Robotic Control Systems
How to Design Distributed Robotic Control SystemsHow to Design Distributed Robotic Control Systems
How to Design Distributed Robotic Control SystemsReal-Time Innovations (RTI)
 
Smart Parking Concept - An Internet of Things Solution
Smart Parking Concept - An Internet of Things SolutionSmart Parking Concept - An Internet of Things Solution
Smart Parking Concept - An Internet of Things SolutionrapidBizApps
 
Validation Framework for Autonomous Aerial Vehicles
Validation Framework for Autonomous Aerial VehiclesValidation Framework for Autonomous Aerial Vehicles
Validation Framework for Autonomous Aerial VehiclesM. Ilhan Akbas
 
IMS Traffic Intelligence through Crowdsourcing phone signals
IMS Traffic Intelligence through Crowdsourcing phone signalsIMS Traffic Intelligence through Crowdsourcing phone signals
IMS Traffic Intelligence through Crowdsourcing phone signalsBlair Currie
 
ClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
ClueCon 2018: AI For Real-time Communications by Binoy ChemmagateClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
ClueCon 2018: AI For Real-time Communications by Binoy Chemmagatecallstats.io
 
Zig bee based vehicle access control system
Zig bee based vehicle access control systemZig bee based vehicle access control system
Zig bee based vehicle access control systemRudra Pratap Singh
 
How to Solve the Data Challenge in Connected Transport
How to Solve the Data Challenge in Connected TransportHow to Solve the Data Challenge in Connected Transport
How to Solve the Data Challenge in Connected TransportKnowi
 
Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12Barry Gander
 
Architecture & data acquisition by embedded systems in automobiles seminar ppt
Architecture & data acquisition by embedded systems in automobiles seminar pptArchitecture & data acquisition by embedded systems in automobiles seminar ppt
Architecture & data acquisition by embedded systems in automobiles seminar pptAnkit Kaul
 
V2X Communications: Getting our Cars Talking
V2X Communications: Getting our Cars TalkingV2X Communications: Getting our Cars Talking
V2X Communications: Getting our Cars TalkingAlison Chaiken
 
Cloud Security - Cloud Arena - Tim Willoughby
Cloud Security - Cloud Arena - Tim WilloughbyCloud Security - Cloud Arena - Tim Willoughby
Cloud Security - Cloud Arena - Tim WilloughbyTim Willoughby
 

Similar a Connected vehicles (20)

Will Your Car Betray you
Will Your Car Betray youWill Your Car Betray you
Will Your Car Betray you
 
Internet: Its Past, Present and The Future
Internet: Its Past, Present and The FutureInternet: Its Past, Present and The Future
Internet: Its Past, Present and The Future
 
Secrets of Autonomous Car Design
Secrets of Autonomous Car DesignSecrets of Autonomous Car Design
Secrets of Autonomous Car Design
 
Mobile application testing
Mobile application testingMobile application testing
Mobile application testing
 
The Cloud and the Car
The Cloud and the CarThe Cloud and the Car
The Cloud and the Car
 
Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010
 
How to Design Distributed Robotic Control Systems
How to Design Distributed Robotic Control SystemsHow to Design Distributed Robotic Control Systems
How to Design Distributed Robotic Control Systems
 
Smart Parking Concept - An Internet of Things Solution
Smart Parking Concept - An Internet of Things SolutionSmart Parking Concept - An Internet of Things Solution
Smart Parking Concept - An Internet of Things Solution
 
Validation Framework for Autonomous Aerial Vehicles
Validation Framework for Autonomous Aerial VehiclesValidation Framework for Autonomous Aerial Vehicles
Validation Framework for Autonomous Aerial Vehicles
 
Smart parking
Smart parkingSmart parking
Smart parking
 
Secure you
Secure you Secure you
Secure you
 
IMS Traffic Intelligence through Crowdsourcing phone signals
IMS Traffic Intelligence through Crowdsourcing phone signalsIMS Traffic Intelligence through Crowdsourcing phone signals
IMS Traffic Intelligence through Crowdsourcing phone signals
 
ClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
ClueCon 2018: AI For Real-time Communications by Binoy ChemmagateClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
ClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
 
Zig bee based vehicle access control system
Zig bee based vehicle access control systemZig bee based vehicle access control system
Zig bee based vehicle access control system
 
How to Solve the Data Challenge in Connected Transport
How to Solve the Data Challenge in Connected TransportHow to Solve the Data Challenge in Connected Transport
How to Solve the Data Challenge in Connected Transport
 
Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12
 
CCTV in the CLOUD
CCTV in the CLOUDCCTV in the CLOUD
CCTV in the CLOUD
 
Architecture & data acquisition by embedded systems in automobiles seminar ppt
Architecture & data acquisition by embedded systems in automobiles seminar pptArchitecture & data acquisition by embedded systems in automobiles seminar ppt
Architecture & data acquisition by embedded systems in automobiles seminar ppt
 
V2X Communications: Getting our Cars Talking
V2X Communications: Getting our Cars TalkingV2X Communications: Getting our Cars Talking
V2X Communications: Getting our Cars Talking
 
Cloud Security - Cloud Arena - Tim Willoughby
Cloud Security - Cloud Arena - Tim WilloughbyCloud Security - Cloud Arena - Tim Willoughby
Cloud Security - Cloud Arena - Tim Willoughby
 

Último

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoffsammart93
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businesspanagenda
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Jeffrey Haguewood
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelDeepika Singh
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...Zilliz
 

Último (20)

Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
WSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering DevelopersWSO2's API Vision: Unifying Control, Empowering Developers
WSO2's API Vision: Unifying Control, Empowering Developers
 
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
Web Form Automation for Bonterra Impact Management (fka Social Solutions Apri...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 

Connected vehicles

  • 1. Privacy and the Car of the Future Consideration for the coming connected vehicle
  • 2. whoami • BSEE, digital communications • Many years as a network engineer • Santa Clara University Law student • Research assistant providing technical expertise on privacy audits and reviews • Contracted by auto consortium to review privacy of proposed vehicle to vehicle safety network
  • 3. Standard Disclaimer IANAL (Yet) But if you know anyone looking for summer interns....
  • 4. Non-Standard Disclaimer A current NDA covers some of my work here (but not very much) The focus will be on published information and standards.
  • 5. What is This Project? • DSRC: Dedicated Short Range Communications • (Where “short” == 380m) • Vehicle to Vehicle • Vehicle to infrastructure in Europe - Not having to wait for a light on an empty street again. - Better traffic planning for better cities and roadways.
  • 6. Why is It being Developed? Safety Photo Credit: Jason Edward Scott Bain
  • 7. Non-trivial Impact on Auto Deaths • World Health Organization estimates 25% of vehicle deaths each year can be prevented. • Fatigue and distracted driving accidents reduced. • Blind Corners, fog and limited visibility accidents reduced. Photo: Public Domain
  • 8. Will This really Happen? IT ALREADY IS
  • 9. How Soon? • Hardware is already being shipped. • Software issues still entirely in the air • More is being done in software these days. • The US Dept. of Transportation is considering mandating this for all new cars. (Decision to come later this year.) • Has already deployed in trucks in Europe
  • 10. What is DSRC • Basic safety messages sent out every 1/10 seconds. • All message carry a standard glob: values for pre-defined vehicle trajectory and operational data. • Cars process data and warn driver. • Equipment integrated into vehicle Photo Credit: US Dept. of Transportation
  • 11. Photo Credit: NIST AfterMarket Installation A little cumbersome
  • 12. What DSRC is not • CANbus • OnStar (or any other remote service) • (Direct) support for autonomous driving mechanisms. Photo Credit: US Dept. of Transportation
  • 14. Radio protocol • 5.9GHz reserved in US and Europe • Signaling standard: IEEE 802.11p / 1609.4 / 1609.3 • Channels reserved for specific functions • No source address for vehicles defined by protocol • Recommendations include using certificates • Privacy challenges at each layer Photo Credit: NASA
  • 15. Basic Safety Message • Standard: SAE J2735 • ~50 fixed data elements • “only” interface to radio (on this band)
  • 16. Parameters for effectiveness • Density • Benefit derived from other vehicles’ use • Greater usage means greater effectiveness • Confidence • Most messages must be trustworthy • People must trust information broadcast
  • 17. Validity? • All messages are cryptographically signed • Signing certificates issued by central authority • Issued based on system fingerprint • Revocation for “malfunctioning” Image source: US Dept. of Transportation equipment • System should invalidate itself if internal checks fail
  • 18. Certificates • Limited time use to prevent tracking • Reused? • Periodically refreshed (and malefactors reported) • How often? • Permanent blacklist
  • 20. MAC Layer • Changeable source (for vehicles) / no destination • Unrouteable! (mostly) • No significant privacy concern as is. • Any algorithm to make network routeable will make vehicles trackable.
  • 21. BSM • “Temporary” ID could become persistent with bad app • Open source apps suggested for processing and acting on message data • Is this the only thing the unit will transmit?
  • 22. Certificates • Identity/Validity conflict • Solution: constantly changing certificates • Revocation by fingerprint • Issuing authority?
  • 23. Fingerprints • “No” correspondence between fingerprint and car • “hard coded” into device • If revoked, entire unit must be replaced to function Photo Credit: NIST
  • 24. Certificate Delivery • Haven’t figured out how certificates are delivered to vehicle • Proposals include cellular, wifi, infrastructure links • So many opportunities for failure
  • 25. Worrisome Noise • Manufacturers want to use this system for commercial apps • Advertising and other “funding” schemes to pay for CA • Fixed infrastructure potentially operated by data brokers
  • 26. Problem: Law Enforcement • What can they do with this? • Correlate location, speed to independent identification? (cameras?) Photo Credit: Alex E. Proimos
  • 27. What you Can Do • Hack the radios • Commercially available now • Hack the protocols • Become politically engaged • Most decisions are not being made by elected officials • Help find a way to fund the infrastructure without selling out!
  • 29. Acknowledgements • Professor Dorothy Glancy, who requested my help on this project • DC 650 (especially Charles Blas) who gave me a reality check with current security and privacy capabilities
  • 30. Contact • Christie Dudley • @longobord • c.dudley@ieee.org

Notas del editor

  1. Current law student. Privacy professor needed help
  2. should not matter But I’m working on that whole “lawyer” thing.
  3. little information to complete the audit. can talk about most published standards
  4. DSRC is a series of protocols. Has changed over the years of development. Black Hat talk: protocols are no longer relevant
  5. collision early warning system. - prevent accidents. - Save lives NHTSA “ distracted ” 2009 (US) stats: Almost 5,000 deaths, est 448,000 injuries Not including other inattention involving physical/emotional state of driver
  6. Good Work - want it to happen . Anecdote: driving in pouring rain too afraid to slow down, too afraid not to.
  7. Large scale testing in Ann Arbor Michigan started last August. Auto makers have already invested heavily in this technology. A few startups here in Silicon Valley to implement this.
  8. American government won’t spend money on infrastructure May be related to “black box” recent US mandate. Trucks have no privacy concerns as they are commercial vehicles.
  9. A system of protocols Not like asn.1 - not data pairs - Map of data
  10. Designed claimed as a “sealed” system, with sensor integrity and accuracy checks.
  11. Automakers lesson from CANbus: insecurity caused no real problems No new tech to mech tech - needs human intervention. “ sealed” sensor system with integrity checks.
  12. HOW it works
  13. Japan doesn’t have the same spectrum available ETSI and FCC approved operating parameters (Biggest difference: US allows more power.) 33 vs 44.7 dBm
  14. Minimum requirement for system. Additional protocols considered in Europe. illustrates general and some specific fields data = whatever’s useful in avoiding collisions
  15. More use = more effective People must trust the system Not just received, but what is sent about them Privacy is important or people will disable it Technological trust is better than laws
  16. Signature and certificate management - on radio Sensor validation (beyond scope here)
  17. Still not nailed down Ann Arbor test: came pre-loaded
  18. This is where we start talking about the FUD
  19. Already pressure for other apps - that need routing. Tension between routing and identifiability
  20. F/OSS Apps kind of neat. Closer to autonomy... Fun: someone in blind spot: “I wouldn’t do that, Dave” - give your vehicle too much power? This is too neat a toy to not use for other things.
  21. Permanent Blacklist? - may not be problem as internet - must replace entire blacklisted unit.
  22. Another problem for anonymity Many schemes to deal with this. Current solution is “no paper trail” We already have certain mistrust of CAs
  23. IEEE 1609 family beyond scope, won’t work - raises many more privacy concerns By the way 9 data brokers took the 5th before Congress in 2006 when asked to reveal the sources of their data.
  24. Tracking, ticketing, whatever else they may want to do.
  25. Fund certificate authority - funding has power.