Security Analysis and Improvement of Vehicle Ethernet SOME/IP Protocol

Sensors (Basel). 2022 Sep 8;22(18):6792. doi: 10.3390/s22186792.

Abstract

The combination of in-vehicle networks and smart car devices has gradually developed into Intelligent Connected Vehicles (ICVs). Through the vehicle security protocol, ICVs can quickly realize communication transmission. However, with the more frequent connections between smart in-vehicle devices and the network, the relationship between intelligent cars and external systems is becoming more and more complicated, and in-vehicle networks are gradually facing many security issues. Strengthening the security of in-vehicle protocols has become particularly important. This paper uses the model building method based on the Colored Petri Net (CPN) theory to model the Scalable service-Oriented MiddlewarE over IP (SOME/IP) protocol of the vehicle Ethernet. The security protocol is formally verified and analyzed by combining it with the Dolev-Yao adversary model detection method. After verification, the protocol is subject to three attack vulnerabilities: replay, tampering, and deception. We introduce timestamps and random numbers to strengthen the protocol security. After the final analysis and verification, the improved scheme in this paper can effectively improve the security performance of the protocol.

Keywords: CPN; Dolev–Yao; ICV; SOME/IP protocol; formal analysis; security evaluation.

Grants and funding

This research was funded by the National Natural Science Foundation of China (grant number 62162039, 61762060) and the Foundation for the Key Research and Development Program of Gansu Province, China (grant number 20YF3GA016), and the Science and Technology Planning Project of Gansu Province, China (grant number 20JR10RA185).