SlideShare a Scribd company logo
1 of 20
Download to read offline
Automotive communication systems :
     from dependability to security

                      Nicolas NAVET
    Real-Time and Interoperability (TRIO) Group at INRIA Nancy




1st Seminar on Vehicular Communications and Applications (VCA 2011)
NetLab / SnT, Luxembourg - 30/05/2011
Dependability vs Security [from Laprie et al, ref.3]
                                                                  “absence of unauthorized access to,
                                                                     or handling of, system state”
                       “ability to
                        deliver a
                      service that               Dependability                         Security
                     can justifiably
                      be trusted ”




       Availability               Reliability   Safety   Confidentiality   Integrity     Maintenability
  Readiness for Continuity of Absence of    Absence of                     Absence of         Ability to
      usage       service    catastrophic unauthorized                      improper          undergo
                            consequences disclosure of                       system         repairs and
 for authorized                            information                     alterations       evolutions
     users only
                                                                        “unauthorized”
                                                                       system alteration

© 2011 INRIA / RealTime-at-Work - 2
Outline
         1.         Trends in automotive embedded systems: increasing
                    safety requirements and complexity

         2.         The (numerous) impediments/threats to dependability:
                    with a focus on timing constraints verification

         3.         Security against malicious attacks : physical access to the
                    vehicle or wireless access

                           Focus on the verification issues at the development phase
                     of the communication systems - highlight issues, not about solutions



© 2011 INRIA / RealTime-at-Work - 3
Electronics is the driving force of innovation
     Many new functions are safety
  critical: brake assist, cruise control,
   lane keeping, dynamic lights, etc

                                                                                   Picture from [10]

                                  –    90% of new functions use software
                                  –    Electronics: 40% of total costs
                                  –    Huge complexity: 70 ECUs, 2500 signals,
                                      >6 comm. protocols, multi-layered run-time
                                      environment (AUTOSAR), multi-source
                                      software, multi-core CPUs, number of
                                      variants, etc



                              Strong costs and time-to-market constraints !

© 2011 INRIA / RealTime-at-Work - 4
BMW 7 Series networking architecture [10]

                                                          ZGW = central
                                                         gateway
                                                          4 CAN buses
                                                          1 FlexRay Bus
                                                          1 MOST bus
                                                           Several LIN Buses
                                                         (not shown here)
                                                          1 Ethernet bus
                                                          Wireless



                                      Picture from [4]

© 2011 INRIA / RealTime-at-Work - 5
Impediments to safety: complexity!
    Technologies: numerous, complex and not
       explicit. conceived for critical systems
    – e.g.: more than 150 specification documents
       (textual) for Autosar, no two implementations
       can behave identically!
    Size of the system!
    – Number of functional domains, buses, gateways,           Autosar Basic Software
       ECUs, size of code, tasks, wiring, number of
       variants, etc
    Design process
    – Most developments are not done in-house :
       less control on externalized developments
    – Carry-over / Vehicle Family Management : need to
       share/re-use architecture and sub-systems between
       several brands/models with different requirements [2]
    – Optimized solutions for each component / function
       does not lead to a global optimal! [2]                          Wiring harness
                                                               Picture from [4]


© 2011 INRIA / RealTime-at-Work - 6
impediments to safety: cultural/regulatory
              Eg: Automotive embedded systems have not been designed
              with the same standards as airplanes - different tradeoff costs
              / safety :
                     little (no?) fault-tolerance using hardware redundancy
                     Technical parameters are regarded as less important than cost for
                     supplier / components selection [2]
                     ISO2626-2 upcoming standard: no safety quantification, in-house
                     certification accepted
                     Lack well-accepted design process, decision on experience, “gut-
                     feeling”, poor tool support [2]
                     Verification / validation does not ensure 100% coverage


                                      Formal verification is gaining acceptance:
                                         code analysis, timing analysis, etc

© 2011 INRIA / RealTime-at-Work - 7
Threats to safety :
                                  the case of timing constraints




© 2011 INRIA / RealTime-at-Work - 8
Several hundreds of timing constraints:
                  responsiveness, data refresh rate


                                          Constraint :
                                      brake light on < 50ms




   Stimulus                                                       Response




                                               Figure from [12]

© 2011 INRIA / RealTime-at-Work - 9
Why timing constraints may not be respected
                            occasionally?
                                                                                           Middleware
  Lack of precise specification : hard to identify                                              Frame-packing task
                                                                                      5ms
     the right timing requirements for each function
  Lack of traceability : from the architects to the suppliers
  Flaws in the verification:
  – Knowledge of the system and its environment is incomplete:                                      Waiting queue:
          •      What is done by the suppliers?
                                                                                                    - FIFO
          •      Implementation choices really matter and standards do
                 not say everything                                                         2       - Highest Priority
          •      Environmental issues: EMI, α-particles, heat, etc                                    First
          •      Traffic is not always well characterized and/or well modeled               1       - OEM specific
                 e.g. aperiodic traffic ?! see [5]
  –     Testing /simulation alone is not enough                                       CAN Controller
  –     Analysis is not enough too:
          •      Analytic models, especially complex ones, can be wrong                9        6       8
                 (remember “ CAN analysis refuted, revisited, etc” [6] ?!)
          •      They are often much simplified abstraction of reality                                buffer Tx
                 and might become optimistic: neglect FIFOs, hardware limitations
                                                                                    CAN Bus

© 2011 INRIA / RealTime-at-Work - 10
Illustration: Worst-Case Response Times on a CAN bus
                Frame waiting queues are HPF, except ECU1 where queue is FIFO
               the OEM does not know or verification software cannot handle it …


  Analysis Setup:
  -     Typical body network with 15 ECUs
        generated by NETCARbench (freely available)
  -     WCRT computed with NETCAR-Analyzer
        (freely available)




                                         Many high-priority frames are delayed here because
                                            a single ECU (out of 15) has a FIFO queue …


© 2011 INRIA / RealTime-at-Work - 11
Threats to dependability:
                         Faults → errors → service failures [3]
     When faults are introduced in the development phase ?
     –     Requirements capture + Specification + SW development: 99% (infineon [10])
     –     HW development : ε


     Why ? The factors :
     – Technologies: not conceived with dependability as a priority
     – Complexity / size of the system
     – Developments are mainly externalized
     – Strong cost / time-to-market pressure
     – Limited regulatory constraints
     – Limited used of formal methods for verification
     – Human factors
     – etc



© 2011 INRIA / RealTime-at-Work - 12
Security : some identified risks and
                                     scenarios




© 2011 INRIA / RealTime-at-Work - 13
Security : two scenarios
         Case 1 : attackers have physical access to the vehicle
                  −         Easy to get access to internal networks through the On-Board
                            Diagnostic (OBDII) port
                  −         AFAIK, automotive systems are not protected at all
                  −         Open question: should we go beyond basic protection measures?
                            Can we afford it?

        Case 2 : remote access through wireless networks
                −          Strong protection needed against remote attacks because of
                           Internet access, manufacturer telematics services, Car-to-Car &
                           Car-to-infrastructure communication, , etc
                −          Open question: is it the case today ?


© 2011 INRIA / RealTime-at-Work - 14
Physical access to the vehicle:
                                  experiments in [11]
                                       Connection to the OBD-II port

                                        Attacks performed :
       Picture from [11]
                                        – Manipulate speedometer
                                        – Injection of malicious code by re-flashing ECUs
                                           (while driving!)
                                        – Disable communications on the CAN buses
                                        – Disable all lights
                                        – Stop the engine
                                        – Disable / lock (specific) brakes
                                        – Were able to manipulate all ECUs!



© 2011 INRIA / RealTime-at-Work - 15
Attacks through the wireless interfaces
                        Issue: there are a number of ECUs that have access to both the
                           internal networks and wireless networks, e.g. radio player,
                            bluetooth transmitters, wireless tire pressure sensors, etc


                                                                      Code injection in other ECUs,
                          Code injection                              Denial-of-service by flooding,
                          external attack                                   Falsification, etc



                                    Telematics &                     Networks for
                                 Multimedia networks               real-time control
                                  (wired / wireless )               (CAN, FlexRay, Lin)




                                       An “infected” vehicle may contaminate others.


© 2011 INRIA / RealTime-at-Work - 16
Virtualization as a means to enforce security
          Example: Radio-player or Body Control Module with both an infotainment
          (eg., Linux, Android) and an Autosar Virtual Machine (VM)


         Communication between VMs through
         the hypervisor “secure” mechanisms



     Benefits
     –     Security despite open systems                               Hypervisor

     –     Preserve segregation in “vehicle domains”
     –     Best of both worlds in terms of know-how,
                                                          Telematics &                Networks for
           time-to-market
                                                       Multimedia networks          real-time control
     –     etc                                          (wired / wireless )         (CAN, FlexRay, Lin)


           A likely use-case of virtualization – open questions: which technical solutions?
                   role/business model among actors? change wrt aftermarket? etc

© 2011 INRIA / RealTime-at-Work - 17
References




© 2011 INRIA / RealTime-at-Work - 18
References                           [1] N. Navet, F. Simonot-Lion, editors, The Automotive Embedded Systems
                                           Handbook, Industrial Information Technology series, CRC Press / Taylor and
                                           Francis, ISBN 978-0849380266, December 2008.
                                       [2] RealTime-at-Work (RTaW), RTaW-Sim: a Fine-Grained Simulator of Controller
                                           Area Network with Fault-Injection Capabilities, freely available on RTaW web
                                           site: http://www.realtimeatwork.com, 2010.
                                       [3] A. Avizienis, J.C. Laprie, B. Randell, “Dependability and its threat: a
                                           taxonomy", IFIP Congress Topical Sessions 2004.
                                       [4] D. Khan, R. Bril, N. Navet, “Integrating Hardware Limitations in CAN
                                           Schedulability Analysis“, WiP at the 8th IEEE International Workshop on
                                           Factory Communication Systems (WFCS 2010), Nancy, France, May 2010.
                                       [5] D. Khan, N. Navet, B. Bavoux, J. Migge, “Aperiodic Traffic in Response Time
                                           Analyses with Adjustable Safety Level“, IEEE ETFA2009, Mallorca, Spain,
                                           September 22-26, 2009.
                                       [6] R. Davis, A. Burn, R. Bril, and J. Lukkien, “Controller Area Network (CAN)
                                           schedulability analysis: Refuted, revisited and revised”, Real-Time Systems,
                                           vol. 35, pp. 239–272, 2007.
                                       [7] M. D. Natale, “Evaluating message transmission times in Controller Area
                                           Networks without buffer preemption”, in 8th Brazilian Workshop on Real-Time
                                           Systems, 2006.
                                       [8] C. Braun, L. Havet, N. Navet, "NETCARBENCH: a benchmark for techniques
                                           and tools used in the design of automotive communication systems", Proc IFAC
                                           FeT 2007, Toulouse, France, November 7-9, 2007.
                                       [9] R. Kaiser, D. Zöbel, “Quantitative Analysis and Systematic Parametrization of a
                                           Two-Level Real-Time Scheduler”, paper and slides at IEEE ETFA’2009.
                                       [10] P. Leteinturier, “Next Generation Powertrain Microcontrollers”, International
                                           Automotive Electronics Congress, November 2007.
                                       [11] K. Koscher et al, “Experimental Security Analysis of a Modern Automobile”,
                                           IEEE Symposium on Security and Privacy, 2010.
                                       [12] AUTOSAR, “Specification of Timing Extensions”, Release 4.0 Rev 2, 2010.


© 2011 INRIA / RealTime-at-Work - 19
Questions / feedback ?




                                        Please get in touch at :
                                         nicolas.navet@inria.fr



© 2011 INRIA / RealTime-at-Work - 20

More Related Content

What's hot

Do We Really Need TSN in Next-Generation Helicopters? Insights From a Case-Study
Do We Really Need TSN in Next-Generation Helicopters? Insights From a Case-StudyDo We Really Need TSN in Next-Generation Helicopters? Insights From a Case-Study
Do We Really Need TSN in Next-Generation Helicopters? Insights From a Case-StudyRealTime-at-Work (RTaW)
 
In‐Vehicle Networking: a Survey and Look Forward
In‐Vehicle Networking: a Survey and Look ForwardIn‐Vehicle Networking: a Survey and Look Forward
In‐Vehicle Networking: a Survey and Look ForwardRealTime-at-Work (RTaW)
 
Early-stage topological and technological choices for TSN-based communication...
Early-stage topological and technological choices for TSN-based communication...Early-stage topological and technological choices for TSN-based communication...
Early-stage topological and technological choices for TSN-based communication...RealTime-at-Work (RTaW)
 
CAN in Automotive Applications: a Look Forward
CAN in Automotive Applications: a Look ForwardCAN in Automotive Applications: a Look Forward
CAN in Automotive Applications: a Look ForwardRealTime-at-Work (RTaW)
 
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture DesignTowards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture DesignRealTime-at-Work (RTaW)
 
OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...
OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...
OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...Pankaj Singh
 
SDN Summit - Optical SDN: Virtualizing the Transport Network
SDN Summit - Optical SDN: Virtualizing the Transport NetworkSDN Summit - Optical SDN: Virtualizing the Transport Network
SDN Summit - Optical SDN: Virtualizing the Transport NetworkADVA
 
What is-twamp
What is-twampWhat is-twamp
What is-twampNir Cohen
 
Optical Transport SDN by Peter Landon [APRICOT 2015]
Optical Transport SDN by Peter Landon [APRICOT 2015]Optical Transport SDN by Peter Landon [APRICOT 2015]
Optical Transport SDN by Peter Landon [APRICOT 2015]APNIC
 
Ethernet OAM (fujitsu)
Ethernet OAM (fujitsu)Ethernet OAM (fujitsu)
Ethernet OAM (fujitsu)Puran Pangeni
 
60936529 55241452-kpi-3 g-3[1]
60936529 55241452-kpi-3 g-3[1]60936529 55241452-kpi-3 g-3[1]
60936529 55241452-kpi-3 g-3[1]picaraza9
 
IPTV QoE Monitoring
IPTV QoE MonitoringIPTV QoE Monitoring
IPTV QoE MonitoringYoss Cohen
 
Phase Delivery in Brownfield World at ITSF 2014
Phase Delivery in Brownfield World at ITSF 2014Phase Delivery in Brownfield World at ITSF 2014
Phase Delivery in Brownfield World at ITSF 2014ADVA
 
Ethernet vs-mpls-tp-in-the-access-presentation
Ethernet vs-mpls-tp-in-the-access-presentationEthernet vs-mpls-tp-in-the-access-presentation
Ethernet vs-mpls-tp-in-the-access-presentationNir Cohen
 
Euro india2006 wirelessradioembeddedchallenges
Euro india2006 wirelessradioembeddedchallengesEuro india2006 wirelessradioembeddedchallenges
Euro india2006 wirelessradioembeddedchallengesArpan Pal
 
PLNOG16: Bringing SDN outside the cloud and datacenter, Johnny Hedlund
PLNOG16: Bringing SDN outside the cloud and datacenter, Johnny HedlundPLNOG16: Bringing SDN outside the cloud and datacenter, Johnny Hedlund
PLNOG16: Bringing SDN outside the cloud and datacenter, Johnny HedlundPROIDEA
 
Automotive network and gateway simulation
Automotive network and gateway simulationAutomotive network and gateway simulation
Automotive network and gateway simulationDeepak Shankar
 
PowerArtist: RTL Design for Power Platform
PowerArtist: RTL Design for Power PlatformPowerArtist: RTL Design for Power Platform
PowerArtist: RTL Design for Power PlatformAnsys
 

What's hot (20)

Do We Really Need TSN in Next-Generation Helicopters? Insights From a Case-Study
Do We Really Need TSN in Next-Generation Helicopters? Insights From a Case-StudyDo We Really Need TSN in Next-Generation Helicopters? Insights From a Case-Study
Do We Really Need TSN in Next-Generation Helicopters? Insights From a Case-Study
 
In‐Vehicle Networking: a Survey and Look Forward
In‐Vehicle Networking: a Survey and Look ForwardIn‐Vehicle Networking: a Survey and Look Forward
In‐Vehicle Networking: a Survey and Look Forward
 
Early-stage topological and technological choices for TSN-based communication...
Early-stage topological and technological choices for TSN-based communication...Early-stage topological and technological choices for TSN-based communication...
Early-stage topological and technological choices for TSN-based communication...
 
CAN in Automotive Applications: a Look Forward
CAN in Automotive Applications: a Look ForwardCAN in Automotive Applications: a Look Forward
CAN in Automotive Applications: a Look Forward
 
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture DesignTowards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
 
OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...
OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...
OVERCOMING KEY CHALLENGES OF TODAY'S COMPLEX SOC: PERFORMANCE OPTIMIZATION AN...
 
SDN Summit - Optical SDN: Virtualizing the Transport Network
SDN Summit - Optical SDN: Virtualizing the Transport NetworkSDN Summit - Optical SDN: Virtualizing the Transport Network
SDN Summit - Optical SDN: Virtualizing the Transport Network
 
Lakhan_Gupta_CV
Lakhan_Gupta_CVLakhan_Gupta_CV
Lakhan_Gupta_CV
 
What is-twamp
What is-twampWhat is-twamp
What is-twamp
 
Optical Transport SDN by Peter Landon [APRICOT 2015]
Optical Transport SDN by Peter Landon [APRICOT 2015]Optical Transport SDN by Peter Landon [APRICOT 2015]
Optical Transport SDN by Peter Landon [APRICOT 2015]
 
Ethernet OAM (fujitsu)
Ethernet OAM (fujitsu)Ethernet OAM (fujitsu)
Ethernet OAM (fujitsu)
 
60936529 55241452-kpi-3 g-3[1]
60936529 55241452-kpi-3 g-3[1]60936529 55241452-kpi-3 g-3[1]
60936529 55241452-kpi-3 g-3[1]
 
IPTV QoE Monitoring
IPTV QoE MonitoringIPTV QoE Monitoring
IPTV QoE Monitoring
 
Phase Delivery in Brownfield World at ITSF 2014
Phase Delivery in Brownfield World at ITSF 2014Phase Delivery in Brownfield World at ITSF 2014
Phase Delivery in Brownfield World at ITSF 2014
 
Ethernet vs-mpls-tp-in-the-access-presentation
Ethernet vs-mpls-tp-in-the-access-presentationEthernet vs-mpls-tp-in-the-access-presentation
Ethernet vs-mpls-tp-in-the-access-presentation
 
Euro india2006 wirelessradioembeddedchallenges
Euro india2006 wirelessradioembeddedchallengesEuro india2006 wirelessradioembeddedchallenges
Euro india2006 wirelessradioembeddedchallenges
 
PLNOG16: Bringing SDN outside the cloud and datacenter, Johnny Hedlund
PLNOG16: Bringing SDN outside the cloud and datacenter, Johnny HedlundPLNOG16: Bringing SDN outside the cloud and datacenter, Johnny Hedlund
PLNOG16: Bringing SDN outside the cloud and datacenter, Johnny Hedlund
 
Automotive network and gateway simulation
Automotive network and gateway simulationAutomotive network and gateway simulation
Automotive network and gateway simulation
 
Umts Kpi
Umts KpiUmts Kpi
Umts Kpi
 
PowerArtist: RTL Design for Power Platform
PowerArtist: RTL Design for Power PlatformPowerArtist: RTL Design for Power Platform
PowerArtist: RTL Design for Power Platform
 

Viewers also liked

Embedding Linux For An Automotive Environment
Embedding Linux For An Automotive EnvironmentEmbedding Linux For An Automotive Environment
Embedding Linux For An Automotive EnvironmentFSCONS
 
erocci - a scalable model-driven API framework, OW2con'16, Paris.
erocci - a scalable model-driven API framework, OW2con'16, Paris. erocci - a scalable model-driven API framework, OW2con'16, Paris.
erocci - a scalable model-driven API framework, OW2con'16, Paris. OCCIware
 
01072013 e governance
01072013 e governance01072013 e governance
01072013 e governancebharati k
 
Yet Another Three QVT Languages
Yet Another Three QVT LanguagesYet Another Three QVT Languages
Yet Another Three QVT LanguagesEdward Willink
 
Model Transformation A Personal Perspective
Model Transformation A Personal PerspectiveModel Transformation A Personal Perspective
Model Transformation A Personal PerspectiveEdward Willink
 
Modeling the OCL Standard Library
Modeling the OCL Standard LibraryModeling the OCL Standard Library
Modeling the OCL Standard LibraryEdward Willink
 
The Importance of Opposites
The Importance of OppositesThe Importance of Opposites
The Importance of OppositesEdward Willink
 
Design Thinking Assignment
Design Thinking AssignmentDesign Thinking Assignment
Design Thinking AssignmentSalma ES-Salmani
 
النشاط العلمي - الكهرباء
النشاط العلمي  -   الكهرباءالنشاط العلمي  -   الكهرباء
النشاط العلمي - الكهرباءErradi Mohamed
 
mis
mismis
misISIG
 
Embedded OCL Integration and Debugging
Embedded OCL Integration and DebuggingEmbedded OCL Integration and Debugging
Embedded OCL Integration and DebuggingEdward Willink
 
Ressource numérique Circuit électrique au primaire
Ressource numérique Circuit électrique au primaire Ressource numérique Circuit électrique au primaire
Ressource numérique Circuit électrique au primaire Erradi Mohamed
 
SysML adoption in France
SysML adoption in FranceSysML adoption in France
SysML adoption in FrancePascal Roques
 
OCL Specification Status
OCL Specification StatusOCL Specification Status
OCL Specification StatusEdward Willink
 
OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...
OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...
OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...OCCIware
 
Timing verification of automotive communication architecture using quantile ...
Timing verification of automotive communication  architecture using quantile ...Timing verification of automotive communication  architecture using quantile ...
Timing verification of automotive communication architecture using quantile ...RealTime-at-Work (RTaW)
 

Viewers also liked (20)

Embedding Linux For An Automotive Environment
Embedding Linux For An Automotive EnvironmentEmbedding Linux For An Automotive Environment
Embedding Linux For An Automotive Environment
 
erocci - a scalable model-driven API framework, OW2con'16, Paris.
erocci - a scalable model-driven API framework, OW2con'16, Paris. erocci - a scalable model-driven API framework, OW2con'16, Paris.
erocci - a scalable model-driven API framework, OW2con'16, Paris.
 
Java vs .Net
Java vs .NetJava vs .Net
Java vs .Net
 
Mix
MixMix
Mix
 
01072013 e governance
01072013 e governance01072013 e governance
01072013 e governance
 
Yet Another Three QVT Languages
Yet Another Three QVT LanguagesYet Another Three QVT Languages
Yet Another Three QVT Languages
 
Model Transformation A Personal Perspective
Model Transformation A Personal PerspectiveModel Transformation A Personal Perspective
Model Transformation A Personal Perspective
 
Modeling the OCL Standard Library
Modeling the OCL Standard LibraryModeling the OCL Standard Library
Modeling the OCL Standard Library
 
The Importance of Opposites
The Importance of OppositesThe Importance of Opposites
The Importance of Opposites
 
UMLX and QVT and ATL
UMLX and QVT and ATLUMLX and QVT and ATL
UMLX and QVT and ATL
 
Cvl
CvlCvl
Cvl
 
Design Thinking Assignment
Design Thinking AssignmentDesign Thinking Assignment
Design Thinking Assignment
 
النشاط العلمي - الكهرباء
النشاط العلمي  -   الكهرباءالنشاط العلمي  -   الكهرباء
النشاط العلمي - الكهرباء
 
mis
mismis
mis
 
Embedded OCL Integration and Debugging
Embedded OCL Integration and DebuggingEmbedded OCL Integration and Debugging
Embedded OCL Integration and Debugging
 
Ressource numérique Circuit électrique au primaire
Ressource numérique Circuit électrique au primaire Ressource numérique Circuit électrique au primaire
Ressource numérique Circuit électrique au primaire
 
SysML adoption in France
SysML adoption in FranceSysML adoption in France
SysML adoption in France
 
OCL Specification Status
OCL Specification StatusOCL Specification Status
OCL Specification Status
 
OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...
OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...
OCCIware, an extensible, standard-based XaaS consumer platform to manage ever...
 
Timing verification of automotive communication architecture using quantile ...
Timing verification of automotive communication  architecture using quantile ...Timing verification of automotive communication  architecture using quantile ...
Timing verification of automotive communication architecture using quantile ...
 

Similar to Automotive communication systems: from dependability to security

Systèmes embarqués critiques
Systèmes embarqués critiquesSystèmes embarqués critiques
Systèmes embarqués critiquesMarc Daumas
 
Managing application performance for cloud apps bmc
Managing application performance for cloud apps bmcManaging application performance for cloud apps bmc
Managing application performance for cloud apps bmcKhazret Sapenov
 
Oracle - Soluções do device ao Datacenter
Oracle - Soluções do device ao DatacenterOracle - Soluções do device ao Datacenter
Oracle - Soluções do device ao DatacenterGeneXus
 
CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...
CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...
CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...TI Safe
 
Cyber Resiliency 20120420
Cyber Resiliency 20120420Cyber Resiliency 20120420
Cyber Resiliency 20120420Steve Goeringer
 
Andy huckridge
Andy huckridgeAndy huckridge
Andy huckridgeCarl Ford
 
Adaptive fault tolerance_in_real_time_cloud_computing
Adaptive fault tolerance_in_real_time_cloud_computingAdaptive fault tolerance_in_real_time_cloud_computing
Adaptive fault tolerance_in_real_time_cloud_computingwww.pixelsolutionbd.com
 
Security testing in critical systems
Security testing in critical systemsSecurity testing in critical systems
Security testing in critical systemsPeter Wood
 
WIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMSWIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMScscpconf
 
IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...
IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...
IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...IRJET Journal
 
Acceleration_and_Security_draft_v2
Acceleration_and_Security_draft_v2Acceleration_and_Security_draft_v2
Acceleration_and_Security_draft_v2Srinivasa Addepalli
 
Seize the Cloud - Proven Tactics From a Successful Service Provider
Seize the Cloud - Proven Tactics From a Successful Service ProviderSeize the Cloud - Proven Tactics From a Successful Service Provider
Seize the Cloud - Proven Tactics From a Successful Service ProviderCA Nimsoft
 
IRJET- Secure Scheme For Cloud-Based Multimedia Content Storage
IRJET-  	  Secure Scheme For Cloud-Based Multimedia Content StorageIRJET-  	  Secure Scheme For Cloud-Based Multimedia Content Storage
IRJET- Secure Scheme For Cloud-Based Multimedia Content StorageIRJET Journal
 
IRJET- Cross Platform Penetration Testing Suite
IRJET-  	  Cross Platform Penetration Testing SuiteIRJET-  	  Cross Platform Penetration Testing Suite
IRJET- Cross Platform Penetration Testing SuiteIRJET Journal
 
Bryan Singer S4 Presentation
Bryan Singer   S4 PresentationBryan Singer   S4 Presentation
Bryan Singer S4 Presentationbsinger74
 
Case Study: Datalink—Manage IT monitoring the MSP way
Case Study: Datalink—Manage IT monitoring the MSP wayCase Study: Datalink—Manage IT monitoring the MSP way
Case Study: Datalink—Manage IT monitoring the MSP wayCA Technologies
 
Fadi El Moussa Secure Cloud 2012 V2
Fadi El Moussa Secure Cloud 2012 V2Fadi El Moussa Secure Cloud 2012 V2
Fadi El Moussa Secure Cloud 2012 V2fadielmoussa
 
IRJET- Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...
IRJET-  	  Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...IRJET-  	  Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...
IRJET- Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...IRJET Journal
 
WSTA Breakfast Seminar
WSTA Breakfast SeminarWSTA Breakfast Seminar
WSTA Breakfast SeminarJoshua McKenty
 

Similar to Automotive communication systems: from dependability to security (20)

Systèmes embarqués critiques
Systèmes embarqués critiquesSystèmes embarqués critiques
Systèmes embarqués critiques
 
Managing application performance for cloud apps bmc
Managing application performance for cloud apps bmcManaging application performance for cloud apps bmc
Managing application performance for cloud apps bmc
 
Oracle - Soluções do device ao Datacenter
Oracle - Soluções do device ao DatacenterOracle - Soluções do device ao Datacenter
Oracle - Soluções do device ao Datacenter
 
CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...
CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...
CLASS 2018 - Palestra de Julio Oliveira (Gerente de Tecnologia, Power Grids G...
 
Cyber Resiliency 20120420
Cyber Resiliency 20120420Cyber Resiliency 20120420
Cyber Resiliency 20120420
 
Andy huckridge
Andy huckridgeAndy huckridge
Andy huckridge
 
Adaptive fault tolerance_in_real_time_cloud_computing
Adaptive fault tolerance_in_real_time_cloud_computingAdaptive fault tolerance_in_real_time_cloud_computing
Adaptive fault tolerance_in_real_time_cloud_computing
 
Security testing in critical systems
Security testing in critical systemsSecurity testing in critical systems
Security testing in critical systems
 
WIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMSWIRELESS COMPUTING AND IT ECOSYSTEMS
WIRELESS COMPUTING AND IT ECOSYSTEMS
 
IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...
IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...
IRJET- An Efficient Hardware-Oriented Runtime Approach for Stack-Based Softwa...
 
Acceleration_and_Security_draft_v2
Acceleration_and_Security_draft_v2Acceleration_and_Security_draft_v2
Acceleration_and_Security_draft_v2
 
Seize the Cloud - Proven Tactics From a Successful Service Provider
Seize the Cloud - Proven Tactics From a Successful Service ProviderSeize the Cloud - Proven Tactics From a Successful Service Provider
Seize the Cloud - Proven Tactics From a Successful Service Provider
 
IRJET- Secure Scheme For Cloud-Based Multimedia Content Storage
IRJET-  	  Secure Scheme For Cloud-Based Multimedia Content StorageIRJET-  	  Secure Scheme For Cloud-Based Multimedia Content Storage
IRJET- Secure Scheme For Cloud-Based Multimedia Content Storage
 
IRJET- Cross Platform Penetration Testing Suite
IRJET-  	  Cross Platform Penetration Testing SuiteIRJET-  	  Cross Platform Penetration Testing Suite
IRJET- Cross Platform Penetration Testing Suite
 
Airheads vail 2011 air wave overview
Airheads vail 2011   air wave overviewAirheads vail 2011   air wave overview
Airheads vail 2011 air wave overview
 
Bryan Singer S4 Presentation
Bryan Singer   S4 PresentationBryan Singer   S4 Presentation
Bryan Singer S4 Presentation
 
Case Study: Datalink—Manage IT monitoring the MSP way
Case Study: Datalink—Manage IT monitoring the MSP wayCase Study: Datalink—Manage IT monitoring the MSP way
Case Study: Datalink—Manage IT monitoring the MSP way
 
Fadi El Moussa Secure Cloud 2012 V2
Fadi El Moussa Secure Cloud 2012 V2Fadi El Moussa Secure Cloud 2012 V2
Fadi El Moussa Secure Cloud 2012 V2
 
IRJET- Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...
IRJET-  	  Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...IRJET-  	  Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...
IRJET- Analysis of Micro Inversion to Improve Fault Tolerance in High Spe...
 
WSTA Breakfast Seminar
WSTA Breakfast SeminarWSTA Breakfast Seminar
WSTA Breakfast Seminar
 

More from RealTime-at-Work (RTaW)

What are the relevant differences between Asynchronous (ATS) and Credit Based...
What are the relevant differences between Asynchronous (ATS) and Credit Based...What are the relevant differences between Asynchronous (ATS) and Credit Based...
What are the relevant differences between Asynchronous (ATS) and Credit Based...RealTime-at-Work (RTaW)
 
TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?
TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?
TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?RealTime-at-Work (RTaW)
 
Time-Predictable Communication in Service-Oriented Architecture - What are th...
Time-Predictable Communication in Service-Oriented Architecture - What are th...Time-Predictable Communication in Service-Oriented Architecture - What are th...
Time-Predictable Communication in Service-Oriented Architecture - What are th...RealTime-at-Work (RTaW)
 
Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...
Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...
Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...RealTime-at-Work (RTaW)
 
Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...
Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...
Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...RealTime-at-Work (RTaW)
 
Early-stage Bottleneck Identification and Removal in TSN Networks
Early-stage Bottleneck Identification and Removal in TSN NetworksEarly-stage Bottleneck Identification and Removal in TSN Networks
Early-stage Bottleneck Identification and Removal in TSN NetworksRealTime-at-Work (RTaW)
 
Insights into the performance and configuration of TCP in Automotive Ethernet...
Insights into the performance and configuration of TCP in Automotive Ethernet...Insights into the performance and configuration of TCP in Automotive Ethernet...
Insights into the performance and configuration of TCP in Automotive Ethernet...RealTime-at-Work (RTaW)
 
Insights on the Configuration and Performances of SOME/IP Service Discovery
Insights on the Configuration and Performances of SOME/IP Service DiscoveryInsights on the Configuration and Performances of SOME/IP Service Discovery
Insights on the Configuration and Performances of SOME/IP Service DiscoveryRealTime-at-Work (RTaW)
 
Virtualization in Automotive Embedded Systems: an Outlook
Virtualization in Automotive Embedded Systems: an OutlookVirtualization in Automotive Embedded Systems: an Outlook
Virtualization in Automotive Embedded Systems: an OutlookRealTime-at-Work (RTaW)
 
Pushing the limits of Controller Area Network (CAN)
Pushing the limits of Controller Area Network (CAN)Pushing the limits of Controller Area Network (CAN)
Pushing the limits of Controller Area Network (CAN)RealTime-at-Work (RTaW)
 
Ingénierie dirigée par les modèles RTaW
Ingénierie dirigée par les modèles RTaWIngénierie dirigée par les modèles RTaW
Ingénierie dirigée par les modèles RTaWRealTime-at-Work (RTaW)
 

More from RealTime-at-Work (RTaW) (17)

What are the relevant differences between Asynchronous (ATS) and Credit Based...
What are the relevant differences between Asynchronous (ATS) and Credit Based...What are the relevant differences between Asynchronous (ATS) and Credit Based...
What are the relevant differences between Asynchronous (ATS) and Credit Based...
 
TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?
TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?
TSN Timing QoS Mechanisms: What Did We Learn over the Past 10 Years?
 
Time-Predictable Communication in Service-Oriented Architecture - What are th...
Time-Predictable Communication in Service-Oriented Architecture - What are th...Time-Predictable Communication in Service-Oriented Architecture - What are th...
Time-Predictable Communication in Service-Oriented Architecture - What are th...
 
Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...
Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...
Strategies for End-to-End Timing Guarantees in a Centralized Software Defined...
 
Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...
Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...
Signal-Oriented ECUs in a Centralized Service-Oriented Architecture: Scalabil...
 
Early-stage Bottleneck Identification and Removal in TSN Networks
Early-stage Bottleneck Identification and Removal in TSN NetworksEarly-stage Bottleneck Identification and Removal in TSN Networks
Early-stage Bottleneck Identification and Removal in TSN Networks
 
Insights into the performance and configuration of TCP in Automotive Ethernet...
Insights into the performance and configuration of TCP in Automotive Ethernet...Insights into the performance and configuration of TCP in Automotive Ethernet...
Insights into the performance and configuration of TCP in Automotive Ethernet...
 
Insights on the Configuration and Performances of SOME/IP Service Discovery
Insights on the Configuration and Performances of SOME/IP Service DiscoveryInsights on the Configuration and Performances of SOME/IP Service Discovery
Insights on the Configuration and Performances of SOME/IP Service Discovery
 
What fUML can bring to MBSE?
What fUML can bring to MBSE?What fUML can bring to MBSE?
What fUML can bring to MBSE?
 
Multicore scheduling in automotive ECUs
Multicore scheduling in automotive ECUsMulticore scheduling in automotive ECUs
Multicore scheduling in automotive ECUs
 
Virtualization in Automotive Embedded Systems: an Outlook
Virtualization in Automotive Embedded Systems: an OutlookVirtualization in Automotive Embedded Systems: an Outlook
Virtualization in Automotive Embedded Systems: an Outlook
 
Prototypage virtuel à partir de SysML
Prototypage virtuel à partir de SysMLPrototypage virtuel à partir de SysML
Prototypage virtuel à partir de SysML
 
RTaW-Sim Brochure
RTaW-Sim BrochureRTaW-Sim Brochure
RTaW-Sim Brochure
 
Mécanismes de protection AUTOSAR OS
Mécanismes de protection AUTOSAR OSMécanismes de protection AUTOSAR OS
Mécanismes de protection AUTOSAR OS
 
Overview of RTaW SysML-Companion
Overview of RTaW SysML-Companion Overview of RTaW SysML-Companion
Overview of RTaW SysML-Companion
 
Pushing the limits of Controller Area Network (CAN)
Pushing the limits of Controller Area Network (CAN)Pushing the limits of Controller Area Network (CAN)
Pushing the limits of Controller Area Network (CAN)
 
Ingénierie dirigée par les modèles RTaW
Ingénierie dirigée par les modèles RTaWIngénierie dirigée par les modèles RTaW
Ingénierie dirigée par les modèles RTaW
 

Recently uploaded

What Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop WorkingWhat Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop WorkingBruce Cox Imports
 
9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay NagarGenuineGirls
 
Delhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Callshivangimorya083
 
Delhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sex
Delhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sexDelhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sex
Delhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sexshivangimorya083
 
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂Hot Call Girls In Sector 58 (Noida)
 
Production documentary.ppt. x
Production documentary.ppt.               xProduction documentary.ppt.               x
Production documentary.ppt. x21005760
 
Vip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp Number
Vip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp NumberVip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp Number
Vip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp Numberkumarajju5765
 
Vip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile Girls
Vip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile GirlsVip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile Girls
Vip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile Girlsshivangimorya083
 
Hyundai World Rally Team in action at 2024 WRC
Hyundai World Rally Team in action at 2024 WRCHyundai World Rally Team in action at 2024 WRC
Hyundai World Rally Team in action at 2024 WRCHyundai Motor Group
 
Call me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
Call me @ 9892124323 Call Girl in Andheri East With Free Home DeliveryCall me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
Call me @ 9892124323 Call Girl in Andheri East With Free Home DeliveryPooja Nehwal
 
Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...
Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...
Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...amitlee9823
 
如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一
如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一
如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一meq5nzfnk
 
Hauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhi
Hauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhiHauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhi
Hauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhiHot Call Girls In Sector 58 (Noida)
 
Greenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxGreenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxzohiiimughal286
 
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 person
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 personDelhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 person
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 personshivangimorya083
 
꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...
꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...
꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...Hot Call Girls In Sector 58 (Noida)
 
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagardollysharma2066
 
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...Delhi Call girls
 
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdfSales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdfAggregage
 

Recently uploaded (20)

What Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop WorkingWhat Could Cause Your Subaru's Touch Screen To Stop Working
What Could Cause Your Subaru's Touch Screen To Stop Working
 
9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar9990611130 Find & Book Russian Call Girls In Vijay Nagar
9990611130 Find & Book Russian Call Girls In Vijay Nagar
 
Delhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip CallDelhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
Delhi Call Girls Mayur Vihar 9711199171 ☎✔👌✔ Whatsapp Hard And Sexy Vip Call
 
Delhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sex
Delhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sexDelhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sex
Delhi Call Girls Safdarjung 9711199171 ☎✔👌✔Body to body massage with sex
 
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
꧁༒☬ 7042364481 (Call Girl) In Dwarka Delhi Escort Service In Delhi Ncr☬༒꧂
 
Production documentary.ppt. x
Production documentary.ppt.               xProduction documentary.ppt.               x
Production documentary.ppt. x
 
Vip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp Number
Vip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp NumberVip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp Number
Vip Hot Call Girls 🫤 Mahipalpur ➡️ 9711199171 ➡️ Delhi 🫦 Whatsapp Number
 
Call Girls In Greater Noida 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Greater Noida 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICECall Girls In Greater Noida 📱  9999965857  🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
Call Girls In Greater Noida 📱 9999965857 🤩 Delhi 🫦 HOT AND SEXY VVIP 🍎 SERVICE
 
Vip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile Girls
Vip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile GirlsVip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile Girls
Vip Hot🥵 Call Girls Delhi Delhi {9711199012} Avni Thakur 🧡😘 High Profile Girls
 
Hyundai World Rally Team in action at 2024 WRC
Hyundai World Rally Team in action at 2024 WRCHyundai World Rally Team in action at 2024 WRC
Hyundai World Rally Team in action at 2024 WRC
 
Call me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
Call me @ 9892124323 Call Girl in Andheri East With Free Home DeliveryCall me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
Call me @ 9892124323 Call Girl in Andheri East With Free Home Delivery
 
Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...
Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...
Vip Mumbai Call Girls Mumbai Call On 9920725232 With Body to body massage wit...
 
如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一
如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一
如何办理美国西雅图大学毕业证(Seattle毕业证书)成绩单(学位证)原版一比一
 
Hauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhi
Hauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhiHauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhi
Hauz Khas Call Girls ☎ 7042364481 independent Escorts Service in delhi
 
Greenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptxGreenery-Palette Pitch Deck by Slidesgo.pptx
Greenery-Palette Pitch Deck by Slidesgo.pptx
 
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 person
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 personDelhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 person
Delhi Call Girls Saket 9711199171 ☎✔👌✔ Full night Service for more than 1 person
 
꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...
꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...
꧁ ୨⎯Call Girls In Ashok Vihar, New Delhi **✿❀7042364481❀✿**Escorts ServiCes C...
 
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
83778-77756 ( HER.SELF ) Brings Call Girls In Laxmi Nagar
 
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
Call Girls in Malviya Nagar Delhi 💯 Call Us 🔝9205541914 🔝( Delhi) Escorts Ser...
 
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdfSales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
Sales & Marketing Alignment_ How to Synergize for Success.pptx.pdf
 

Automotive communication systems: from dependability to security

  • 1. Automotive communication systems : from dependability to security Nicolas NAVET Real-Time and Interoperability (TRIO) Group at INRIA Nancy 1st Seminar on Vehicular Communications and Applications (VCA 2011) NetLab / SnT, Luxembourg - 30/05/2011
  • 2. Dependability vs Security [from Laprie et al, ref.3] “absence of unauthorized access to, or handling of, system state” “ability to deliver a service that Dependability Security can justifiably be trusted ” Availability Reliability Safety Confidentiality Integrity Maintenability Readiness for Continuity of Absence of Absence of Absence of Ability to usage service catastrophic unauthorized improper undergo consequences disclosure of system repairs and for authorized information alterations evolutions users only “unauthorized” system alteration © 2011 INRIA / RealTime-at-Work - 2
  • 3. Outline 1. Trends in automotive embedded systems: increasing safety requirements and complexity 2. The (numerous) impediments/threats to dependability: with a focus on timing constraints verification 3. Security against malicious attacks : physical access to the vehicle or wireless access Focus on the verification issues at the development phase of the communication systems - highlight issues, not about solutions © 2011 INRIA / RealTime-at-Work - 3
  • 4. Electronics is the driving force of innovation Many new functions are safety critical: brake assist, cruise control, lane keeping, dynamic lights, etc Picture from [10] – 90% of new functions use software – Electronics: 40% of total costs – Huge complexity: 70 ECUs, 2500 signals, >6 comm. protocols, multi-layered run-time environment (AUTOSAR), multi-source software, multi-core CPUs, number of variants, etc Strong costs and time-to-market constraints ! © 2011 INRIA / RealTime-at-Work - 4
  • 5. BMW 7 Series networking architecture [10] ZGW = central gateway 4 CAN buses 1 FlexRay Bus 1 MOST bus Several LIN Buses (not shown here) 1 Ethernet bus Wireless Picture from [4] © 2011 INRIA / RealTime-at-Work - 5
  • 6. Impediments to safety: complexity! Technologies: numerous, complex and not explicit. conceived for critical systems – e.g.: more than 150 specification documents (textual) for Autosar, no two implementations can behave identically! Size of the system! – Number of functional domains, buses, gateways, Autosar Basic Software ECUs, size of code, tasks, wiring, number of variants, etc Design process – Most developments are not done in-house : less control on externalized developments – Carry-over / Vehicle Family Management : need to share/re-use architecture and sub-systems between several brands/models with different requirements [2] – Optimized solutions for each component / function does not lead to a global optimal! [2] Wiring harness Picture from [4] © 2011 INRIA / RealTime-at-Work - 6
  • 7. impediments to safety: cultural/regulatory Eg: Automotive embedded systems have not been designed with the same standards as airplanes - different tradeoff costs / safety : little (no?) fault-tolerance using hardware redundancy Technical parameters are regarded as less important than cost for supplier / components selection [2] ISO2626-2 upcoming standard: no safety quantification, in-house certification accepted Lack well-accepted design process, decision on experience, “gut- feeling”, poor tool support [2] Verification / validation does not ensure 100% coverage Formal verification is gaining acceptance: code analysis, timing analysis, etc © 2011 INRIA / RealTime-at-Work - 7
  • 8. Threats to safety : the case of timing constraints © 2011 INRIA / RealTime-at-Work - 8
  • 9. Several hundreds of timing constraints: responsiveness, data refresh rate Constraint : brake light on < 50ms Stimulus Response Figure from [12] © 2011 INRIA / RealTime-at-Work - 9
  • 10. Why timing constraints may not be respected occasionally? Middleware Lack of precise specification : hard to identify Frame-packing task 5ms the right timing requirements for each function Lack of traceability : from the architects to the suppliers Flaws in the verification: – Knowledge of the system and its environment is incomplete: Waiting queue: • What is done by the suppliers? - FIFO • Implementation choices really matter and standards do not say everything 2 - Highest Priority • Environmental issues: EMI, α-particles, heat, etc First • Traffic is not always well characterized and/or well modeled 1 - OEM specific e.g. aperiodic traffic ?! see [5] – Testing /simulation alone is not enough CAN Controller – Analysis is not enough too: • Analytic models, especially complex ones, can be wrong 9 6 8 (remember “ CAN analysis refuted, revisited, etc” [6] ?!) • They are often much simplified abstraction of reality buffer Tx and might become optimistic: neglect FIFOs, hardware limitations CAN Bus © 2011 INRIA / RealTime-at-Work - 10
  • 11. Illustration: Worst-Case Response Times on a CAN bus Frame waiting queues are HPF, except ECU1 where queue is FIFO the OEM does not know or verification software cannot handle it … Analysis Setup: - Typical body network with 15 ECUs generated by NETCARbench (freely available) - WCRT computed with NETCAR-Analyzer (freely available) Many high-priority frames are delayed here because a single ECU (out of 15) has a FIFO queue … © 2011 INRIA / RealTime-at-Work - 11
  • 12. Threats to dependability: Faults → errors → service failures [3] When faults are introduced in the development phase ? – Requirements capture + Specification + SW development: 99% (infineon [10]) – HW development : ε Why ? The factors : – Technologies: not conceived with dependability as a priority – Complexity / size of the system – Developments are mainly externalized – Strong cost / time-to-market pressure – Limited regulatory constraints – Limited used of formal methods for verification – Human factors – etc © 2011 INRIA / RealTime-at-Work - 12
  • 13. Security : some identified risks and scenarios © 2011 INRIA / RealTime-at-Work - 13
  • 14. Security : two scenarios Case 1 : attackers have physical access to the vehicle − Easy to get access to internal networks through the On-Board Diagnostic (OBDII) port − AFAIK, automotive systems are not protected at all − Open question: should we go beyond basic protection measures? Can we afford it? Case 2 : remote access through wireless networks − Strong protection needed against remote attacks because of Internet access, manufacturer telematics services, Car-to-Car & Car-to-infrastructure communication, , etc − Open question: is it the case today ? © 2011 INRIA / RealTime-at-Work - 14
  • 15. Physical access to the vehicle: experiments in [11] Connection to the OBD-II port Attacks performed : Picture from [11] – Manipulate speedometer – Injection of malicious code by re-flashing ECUs (while driving!) – Disable communications on the CAN buses – Disable all lights – Stop the engine – Disable / lock (specific) brakes – Were able to manipulate all ECUs! © 2011 INRIA / RealTime-at-Work - 15
  • 16. Attacks through the wireless interfaces Issue: there are a number of ECUs that have access to both the internal networks and wireless networks, e.g. radio player, bluetooth transmitters, wireless tire pressure sensors, etc Code injection in other ECUs, Code injection Denial-of-service by flooding, external attack Falsification, etc Telematics & Networks for Multimedia networks real-time control (wired / wireless ) (CAN, FlexRay, Lin) An “infected” vehicle may contaminate others. © 2011 INRIA / RealTime-at-Work - 16
  • 17. Virtualization as a means to enforce security Example: Radio-player or Body Control Module with both an infotainment (eg., Linux, Android) and an Autosar Virtual Machine (VM) Communication between VMs through the hypervisor “secure” mechanisms Benefits – Security despite open systems Hypervisor – Preserve segregation in “vehicle domains” – Best of both worlds in terms of know-how, Telematics & Networks for time-to-market Multimedia networks real-time control – etc (wired / wireless ) (CAN, FlexRay, Lin) A likely use-case of virtualization – open questions: which technical solutions? role/business model among actors? change wrt aftermarket? etc © 2011 INRIA / RealTime-at-Work - 17
  • 18. References © 2011 INRIA / RealTime-at-Work - 18
  • 19. References [1] N. Navet, F. Simonot-Lion, editors, The Automotive Embedded Systems Handbook, Industrial Information Technology series, CRC Press / Taylor and Francis, ISBN 978-0849380266, December 2008. [2] RealTime-at-Work (RTaW), RTaW-Sim: a Fine-Grained Simulator of Controller Area Network with Fault-Injection Capabilities, freely available on RTaW web site: http://www.realtimeatwork.com, 2010. [3] A. Avizienis, J.C. Laprie, B. Randell, “Dependability and its threat: a taxonomy", IFIP Congress Topical Sessions 2004. [4] D. Khan, R. Bril, N. Navet, “Integrating Hardware Limitations in CAN Schedulability Analysis“, WiP at the 8th IEEE International Workshop on Factory Communication Systems (WFCS 2010), Nancy, France, May 2010. [5] D. Khan, N. Navet, B. Bavoux, J. Migge, “Aperiodic Traffic in Response Time Analyses with Adjustable Safety Level“, IEEE ETFA2009, Mallorca, Spain, September 22-26, 2009. [6] R. Davis, A. Burn, R. Bril, and J. Lukkien, “Controller Area Network (CAN) schedulability analysis: Refuted, revisited and revised”, Real-Time Systems, vol. 35, pp. 239–272, 2007. [7] M. D. Natale, “Evaluating message transmission times in Controller Area Networks without buffer preemption”, in 8th Brazilian Workshop on Real-Time Systems, 2006. [8] C. Braun, L. Havet, N. Navet, "NETCARBENCH: a benchmark for techniques and tools used in the design of automotive communication systems", Proc IFAC FeT 2007, Toulouse, France, November 7-9, 2007. [9] R. Kaiser, D. Zöbel, “Quantitative Analysis and Systematic Parametrization of a Two-Level Real-Time Scheduler”, paper and slides at IEEE ETFA’2009. [10] P. Leteinturier, “Next Generation Powertrain Microcontrollers”, International Automotive Electronics Congress, November 2007. [11] K. Koscher et al, “Experimental Security Analysis of a Modern Automobile”, IEEE Symposium on Security and Privacy, 2010. [12] AUTOSAR, “Specification of Timing Extensions”, Release 4.0 Rev 2, 2010. © 2011 INRIA / RealTime-at-Work - 19
  • 20. Questions / feedback ? Please get in touch at : nicolas.navet@inria.fr © 2011 INRIA / RealTime-at-Work - 20