Attack Path Analysis and Security Concept Design for OTA Enabled Electric Power Steering System


Subaşi E., MERCİMEK M.

2024 Innovations in Intelligent Systems and Applications Conference, ASYU 2024, Ankara, Türkiye, 16 - 18 Ekim 2024 identifier

  • Yayın Türü: Bildiri / Tam Metin Bildiri
  • Doi Numarası: 10.1109/asyu62119.2024.10756981
  • Basıldığı Şehir: Ankara
  • Basıldığı Ülke: Türkiye
  • Anahtar Kelimeler: cybersecurity, cybersecurity concept, electric power steering, ISO 21434, over-the-air update
  • Yıldız Teknik Üniversitesi Adresli: Evet

Özet

Electric power steering systems (EPS) are increasingly prevalent in modern vehicles, and over-the-air (OTA) updates offer a convenient method for improving their performance and functionality in the system lifecycle. OTA capability is important to improve control structure with state-of-the-art artificial intelligent (AI) powered novel control algorithms. AI also helps to improve personalized driving characteristics to the best performance. However, OTA capability introduces new security vulnerabilities that could be exploited by attackers. This paper presents a comprehensive analysis of potential attack paths within an OTA-enabled EPS system. Critical components and data flows susceptible to manipulation are identified to manipulation and are explored the potential consequences of successful attacks. Based on this analysis, a security concept is proposed to mitigate these identified risks. Proposed security concepts aim to ensure the integrity and confidentiality of the EPS system throughout the OTA update process. This research contributes to the development of secure and reliable OTA updates for electric power steering systems, promoting safety and functionality in modern vehicles with applying ISO 21434 [1] requirements and recommendations.