SlideShare uma empresa Scribd logo
1 de 30
Privacy and the Car of the
          Future
Consideration for the coming connected vehicle
whoami
•   BSEE, digital communications

•   Many years as a network engineer

•   Santa Clara University Law student

•   Research assistant providing technical expertise on privacy
    audits and reviews

•   Contracted by auto consortium to review privacy of
    proposed vehicle to vehicle safety network
Standard Disclaimer


                IANAL (Yet)
But if you know anyone looking for summer interns....
Non-Standard Disclaimer


A current NDA covers some of my work here (but not very
                           much)
 The focus will be on published information and standards.
What is This Project?

• DSRC: Dedicated Short Range Communications
    •   (Where “short” == 380m)

•   Vehicle to Vehicle

•   Vehicle to infrastructure in Europe
    - Not having to wait for a light on an empty street again.
    - Better traffic planning for better cities and roadways.
Why is It being Developed?



                                        Safety


Photo Credit: Jason Edward Scott Bain
Non-trivial Impact on Auto
                  Deaths
•   World Health Organization
    estimates 25% of vehicle
    deaths each year can be
    prevented.

•   Fatigue and distracted driving
    accidents reduced.

•   Blind Corners, fog and
    limited visibility accidents
    reduced.
                                     Photo: Public Domain
Will This really Happen?




    IT ALREADY IS
How Soon?
•   Hardware is already being shipped.

•   Software issues still entirely in the air

    •   More is being done in software these days.

•   The US Dept. of Transportation is considering mandating
    this for all new cars. (Decision to come later this year.)

•   Has already deployed in trucks in Europe
What is DSRC
•   Basic safety messages sent out
    every 1/10 seconds.

•   All message carry a standard
    glob: values for pre-defined
    vehicle trajectory and
    operational data.

•   Cars process data and warn
    driver.

•   Equipment integrated into
    vehicle                          Photo Credit: US Dept. of Transportation
Photo Credit: NIST




AfterMarket Installation
      A little cumbersome
What DSRC is not
                                           •   CANbus

                                           •   OnStar (or any other
                                               remote service)

                                           •   (Direct) support for
                                               autonomous driving
                                               mechanisms.

Photo Credit: US Dept. of Transportation
Technical details
Radio protocol
•   5.9GHz reserved in US and Europe
•   Signaling standard: IEEE 802.11p /
    1609.4 / 1609.3
•   Channels reserved for specific
    functions
•   No source address for vehicles
    defined by protocol
    •   Recommendations include using
        certificates
    •   Privacy challenges at each layer   Photo Credit: NASA
Basic Safety Message



•   Standard: SAE J2735

•   ~50 fixed data elements

•   “only” interface to radio
    (on this band)
Parameters for effectiveness
•   Density

    •   Benefit derived from other vehicles’ use

    •   Greater usage means greater effectiveness

•   Confidence

    •   Most messages must be trustworthy

    •   People must trust information broadcast
Validity?
•   All messages are
    cryptographically signed

•   Signing certificates issued by
    central authority

•   Issued based on system
    fingerprint

•   Revocation for “malfunctioning”      Image source: US Dept. of Transportation
    equipment

•   System should invalidate itself if
    internal checks fail
Certificates
•   Limited time use to prevent tracking

    •   Reused?

•   Periodically refreshed (and malefactors reported)

    •   How often?

•   Permanent blacklist
Privacy?
MAC Layer

•   Changeable source (for vehicles) / no destination

•   Unrouteable! (mostly)

•   No significant privacy concern as is.

•   Any algorithm to make network routeable will make
    vehicles trackable.
BSM



•   “Temporary” ID could become persistent with bad app

•   Open source apps suggested for processing and acting on
    message data

•   Is this the only thing the unit will transmit?
Certificates


•   Identity/Validity conflict

    •   Solution: constantly changing certificates

    •   Revocation by fingerprint

•   Issuing authority?
Fingerprints


•   “No” correspondence
    between fingerprint and car

•   “hard coded” into device

•   If revoked, entire unit must
    be replaced to function


                                   Photo Credit: NIST
Certificate Delivery

         •   Haven’t figured out how
             certificates are delivered to
             vehicle

         •   Proposals include cellular,
             wifi, infrastructure links

         •   So many opportunities for
             failure
Worrisome Noise



•   Manufacturers want to use this system for commercial apps

•   Advertising and other “funding” schemes to pay for CA

•   Fixed infrastructure potentially operated by data brokers
Problem: Law
    Enforcement

•   What can they do with this?

•   Correlate location, speed to
    independent identification?
    (cameras?)

                                   Photo Credit: Alex E. Proimos
What you Can Do
•   Hack the radios
    •   Commercially available now

•   Hack the protocols

•   Become politically engaged

    •   Most decisions are not being made by elected officials

    •   Help find a way to fund the infrastructure without selling
        out!
Thank you
Acknowledgements


•   Professor Dorothy Glancy, who requested my help on this
    project

•   DC 650 (especially Charles Blas) who gave me a reality
    check with current security and privacy capabilities
Contact

•   Christie Dudley

•   @longobord

•   c.dudley@ieee.org

Mais conteúdo relacionado

Mais procurados

Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning  Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning 
Junli Gu
 

Mais procurados (20)

The Connected Car: Impact on Wireless Communication
The Connected Car: Impact on Wireless CommunicationThe Connected Car: Impact on Wireless Communication
The Connected Car: Impact on Wireless Communication
 
Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Symphony Teleca - The Connected Car Revolution @ Cebit 2014Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Symphony Teleca - The Connected Car Revolution @ Cebit 2014
 
Future mobile networks connected and autonomous cars
Future mobile networks  connected and autonomous carsFuture mobile networks  connected and autonomous cars
Future mobile networks connected and autonomous cars
 
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
 
IoT for V2V and Connected Car - AW Megatrends `14 panel
IoT for V2V and Connected Car - AW Megatrends `14 panelIoT for V2V and Connected Car - AW Megatrends `14 panel
IoT for V2V and Connected Car - AW Megatrends `14 panel
 
Developing for the Connected Car
Developing for the Connected CarDeveloping for the Connected Car
Developing for the Connected Car
 
2015 Florida Automated Vehicles Initiative - FDOT - FTA
2015 Florida Automated Vehicles Initiative - FDOT - FTA2015 Florida Automated Vehicles Initiative - FDOT - FTA
2015 Florida Automated Vehicles Initiative - FDOT - FTA
 
2017 Autonomous Vehicle Presentation Package
2017 Autonomous Vehicle Presentation Package 2017 Autonomous Vehicle Presentation Package
2017 Autonomous Vehicle Presentation Package
 
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan PetitAutomotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
Automotive Cybersecurity Challenges for Automated Vehicles: Jonathan Petit
 
Connected and Autonomous Vehicle Systems R&D Overview
Connected and Autonomous Vehicle Systems R&D OverviewConnected and Autonomous Vehicle Systems R&D Overview
Connected and Autonomous Vehicle Systems R&D Overview
 
Connected and Automated Vehicles: Where Are We Going and What Happens When We...
Connected and Automated Vehicles: Where Are We Going and What Happens When We...Connected and Automated Vehicles: Where Are We Going and What Happens When We...
Connected and Automated Vehicles: Where Are We Going and What Happens When We...
 
The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19
 
Automotive Exploitation Techniques by Craig Smith
Automotive Exploitation Techniques by Craig SmithAutomotive Exploitation Techniques by Craig Smith
Automotive Exploitation Techniques by Craig Smith
 
Connected Car Investment Thesis
Connected Car Investment ThesisConnected Car Investment Thesis
Connected Car Investment Thesis
 
The Autonomous Revolution of Vehicles and Transportation
The Autonomous Revolution  of Vehicles and TransportationThe Autonomous Revolution  of Vehicles and Transportation
The Autonomous Revolution of Vehicles and Transportation
 
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris ValasekSuns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
Suns Out Guns Out: Hacking without a Vehicle by Charlie Miller & Chris Valasek
 
Addressing Security in the Automotive Industry
Addressing Security in the Automotive IndustryAddressing Security in the Automotive Industry
Addressing Security in the Automotive Industry
 
Connected Cars - Poster Child for the IoT Reality Check
Connected Cars - Poster Child for the IoT Reality CheckConnected Cars - Poster Child for the IoT Reality Check
Connected Cars - Poster Child for the IoT Reality Check
 
Connecting California from Research to Reality
Connecting California from Research to RealityConnecting California from Research to Reality
Connecting California from Research to Reality
 
Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning  Autonomous driving revolution- trends, challenges and machine learning 
Autonomous driving revolution- trends, challenges and machine learning 
 

Destaque

Intelligent transportation systems
Intelligent transportation systemsIntelligent transportation systems
Intelligent transportation systems
Engin Karabulut
 
The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec
Winterwind
 
Black ice technologies rdas (finance)
Black ice technologies rdas (finance)Black ice technologies rdas (finance)
Black ice technologies rdas (finance)
phillyjevs
 
FASTRInfographic2017
FASTRInfographic2017FASTRInfographic2017
FASTRInfographic2017
Craig Hurst
 
Vestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, VestasVestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, Vestas
Winterwind
 
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Jukka Sassi
 
Moving object detection
Moving object detectionMoving object detection
Moving object detection
Manav Mittal
 

Destaque (20)

Intelligent transportation systems
Intelligent transportation systemsIntelligent transportation systems
Intelligent transportation systems
 
The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec The need for ice detection standards Jarkko Latonen, Labkotec
The need for ice detection standards Jarkko Latonen, Labkotec
 
Black ice technologies rdas (finance)
Black ice technologies rdas (finance)Black ice technologies rdas (finance)
Black ice technologies rdas (finance)
 
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEMICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
ICE NAVIGATOR DETECTION AND NAVIGATION SYSTEM
 
Sliding around on an icy road
Sliding around on an icy roadSliding around on an icy road
Sliding around on an icy road
 
Intevencion de espacial
Intevencion de espacialIntevencion de espacial
Intevencion de espacial
 
FASTRInfographic2017
FASTRInfographic2017FASTRInfographic2017
FASTRInfographic2017
 
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
Connected/ Automated Vehicle Privacy Issues: Lessons From Toll Highway Author...
 
Vestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, VestasVestas de-icing development Morten Sloth, Vestas
Vestas de-icing development Morten Sloth, Vestas
 
Braking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle VulnerabilitiesBraking the Connected Car: The Future of Vehicle Vulnerabilities
Braking the Connected Car: The Future of Vehicle Vulnerabilities
 
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
Oil Detection among Ice and Snow_Lessons learned_Sassi_Rytkönen 24 March 2015
 
Electronic Toll Collection Global Study
Electronic Toll Collection Global StudyElectronic Toll Collection Global Study
Electronic Toll Collection Global Study
 
Comparing CoAP vs MQTT
Comparing CoAP vs MQTTComparing CoAP vs MQTT
Comparing CoAP vs MQTT
 
Real Time Object Tracking
Real Time Object TrackingReal Time Object Tracking
Real Time Object Tracking
 
Object tracking
Object trackingObject tracking
Object tracking
 
Moving object detection
Moving object detectionMoving object detection
Moving object detection
 
Electronic Toll Collection System
Electronic Toll Collection SystemElectronic Toll Collection System
Electronic Toll Collection System
 
The Connected Vehicle Movement
The Connected Vehicle MovementThe Connected Vehicle Movement
The Connected Vehicle Movement
 
Internet of Things (IoT) protocols COAP MQTT OSCON2014
Internet of Things (IoT) protocols  COAP MQTT OSCON2014Internet of Things (IoT) protocols  COAP MQTT OSCON2014
Internet of Things (IoT) protocols COAP MQTT OSCON2014
 
Intelligent Transportation System (ITS)
Intelligent Transportation System (ITS)Intelligent Transportation System (ITS)
Intelligent Transportation System (ITS)
 

Semelhante a Connected vehicles

Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010
Iddan Halevy
 
Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12
Barry Gander
 

Semelhante a Connected vehicles (20)

Will Your Car Betray you
Will Your Car Betray youWill Your Car Betray you
Will Your Car Betray you
 
Internet: Its Past, Present and The Future
Internet: Its Past, Present and The FutureInternet: Its Past, Present and The Future
Internet: Its Past, Present and The Future
 
Secrets of Autonomous Car Design
Secrets of Autonomous Car DesignSecrets of Autonomous Car Design
Secrets of Autonomous Car Design
 
Mobile application testing
Mobile application testingMobile application testing
Mobile application testing
 
The Cloud and the Car
The Cloud and the CarThe Cloud and the Car
The Cloud and the Car
 
Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010Feasible car cyber defense - ESCAR 2010
Feasible car cyber defense - ESCAR 2010
 
How to Design Distributed Robotic Control Systems
How to Design Distributed Robotic Control SystemsHow to Design Distributed Robotic Control Systems
How to Design Distributed Robotic Control Systems
 
Smart Parking Concept - An Internet of Things Solution
Smart Parking Concept - An Internet of Things SolutionSmart Parking Concept - An Internet of Things Solution
Smart Parking Concept - An Internet of Things Solution
 
Validation Framework for Autonomous Aerial Vehicles
Validation Framework for Autonomous Aerial VehiclesValidation Framework for Autonomous Aerial Vehicles
Validation Framework for Autonomous Aerial Vehicles
 
Smart parking
Smart parkingSmart parking
Smart parking
 
Secure you
Secure you Secure you
Secure you
 
IMS Traffic Intelligence through Crowdsourcing phone signals
IMS Traffic Intelligence through Crowdsourcing phone signalsIMS Traffic Intelligence through Crowdsourcing phone signals
IMS Traffic Intelligence through Crowdsourcing phone signals
 
ClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
ClueCon 2018: AI For Real-time Communications by Binoy ChemmagateClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
ClueCon 2018: AI For Real-time Communications by Binoy Chemmagate
 
Zig bee based vehicle access control system
Zig bee based vehicle access control systemZig bee based vehicle access control system
Zig bee based vehicle access control system
 
How to Solve the Data Challenge in Connected Transport
How to Solve the Data Challenge in Connected TransportHow to Solve the Data Challenge in Connected Transport
How to Solve the Data Challenge in Connected Transport
 
Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12Cata i canada the cloud and the car diva presentation aug 31 12
Cata i canada the cloud and the car diva presentation aug 31 12
 
CCTV in the CLOUD
CCTV in the CLOUDCCTV in the CLOUD
CCTV in the CLOUD
 
Architecture & data acquisition by embedded systems in automobiles seminar ppt
Architecture & data acquisition by embedded systems in automobiles seminar pptArchitecture & data acquisition by embedded systems in automobiles seminar ppt
Architecture & data acquisition by embedded systems in automobiles seminar ppt
 
V2X Communications: Getting our Cars Talking
V2X Communications: Getting our Cars TalkingV2X Communications: Getting our Cars Talking
V2X Communications: Getting our Cars Talking
 
Cloud Security - Cloud Arena - Tim Willoughby
Cloud Security - Cloud Arena - Tim WilloughbyCloud Security - Cloud Arena - Tim Willoughby
Cloud Security - Cloud Arena - Tim Willoughby
 

Último

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 

Último (20)

Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024Top 10 Most Downloaded Games on Play Store in 2024
Top 10 Most Downloaded Games on Play Store in 2024
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 

Connected vehicles

  • 1. Privacy and the Car of the Future Consideration for the coming connected vehicle
  • 2. whoami • BSEE, digital communications • Many years as a network engineer • Santa Clara University Law student • Research assistant providing technical expertise on privacy audits and reviews • Contracted by auto consortium to review privacy of proposed vehicle to vehicle safety network
  • 3. Standard Disclaimer IANAL (Yet) But if you know anyone looking for summer interns....
  • 4. Non-Standard Disclaimer A current NDA covers some of my work here (but not very much) The focus will be on published information and standards.
  • 5. What is This Project? • DSRC: Dedicated Short Range Communications • (Where “short” == 380m) • Vehicle to Vehicle • Vehicle to infrastructure in Europe - Not having to wait for a light on an empty street again. - Better traffic planning for better cities and roadways.
  • 6. Why is It being Developed? Safety Photo Credit: Jason Edward Scott Bain
  • 7. Non-trivial Impact on Auto Deaths • World Health Organization estimates 25% of vehicle deaths each year can be prevented. • Fatigue and distracted driving accidents reduced. • Blind Corners, fog and limited visibility accidents reduced. Photo: Public Domain
  • 8. Will This really Happen? IT ALREADY IS
  • 9. How Soon? • Hardware is already being shipped. • Software issues still entirely in the air • More is being done in software these days. • The US Dept. of Transportation is considering mandating this for all new cars. (Decision to come later this year.) • Has already deployed in trucks in Europe
  • 10. What is DSRC • Basic safety messages sent out every 1/10 seconds. • All message carry a standard glob: values for pre-defined vehicle trajectory and operational data. • Cars process data and warn driver. • Equipment integrated into vehicle Photo Credit: US Dept. of Transportation
  • 11. Photo Credit: NIST AfterMarket Installation A little cumbersome
  • 12. What DSRC is not • CANbus • OnStar (or any other remote service) • (Direct) support for autonomous driving mechanisms. Photo Credit: US Dept. of Transportation
  • 14. Radio protocol • 5.9GHz reserved in US and Europe • Signaling standard: IEEE 802.11p / 1609.4 / 1609.3 • Channels reserved for specific functions • No source address for vehicles defined by protocol • Recommendations include using certificates • Privacy challenges at each layer Photo Credit: NASA
  • 15. Basic Safety Message • Standard: SAE J2735 • ~50 fixed data elements • “only” interface to radio (on this band)
  • 16. Parameters for effectiveness • Density • Benefit derived from other vehicles’ use • Greater usage means greater effectiveness • Confidence • Most messages must be trustworthy • People must trust information broadcast
  • 17. Validity? • All messages are cryptographically signed • Signing certificates issued by central authority • Issued based on system fingerprint • Revocation for “malfunctioning” Image source: US Dept. of Transportation equipment • System should invalidate itself if internal checks fail
  • 18. Certificates • Limited time use to prevent tracking • Reused? • Periodically refreshed (and malefactors reported) • How often? • Permanent blacklist
  • 20. MAC Layer • Changeable source (for vehicles) / no destination • Unrouteable! (mostly) • No significant privacy concern as is. • Any algorithm to make network routeable will make vehicles trackable.
  • 21. BSM • “Temporary” ID could become persistent with bad app • Open source apps suggested for processing and acting on message data • Is this the only thing the unit will transmit?
  • 22. Certificates • Identity/Validity conflict • Solution: constantly changing certificates • Revocation by fingerprint • Issuing authority?
  • 23. Fingerprints • “No” correspondence between fingerprint and car • “hard coded” into device • If revoked, entire unit must be replaced to function Photo Credit: NIST
  • 24. Certificate Delivery • Haven’t figured out how certificates are delivered to vehicle • Proposals include cellular, wifi, infrastructure links • So many opportunities for failure
  • 25. Worrisome Noise • Manufacturers want to use this system for commercial apps • Advertising and other “funding” schemes to pay for CA • Fixed infrastructure potentially operated by data brokers
  • 26. Problem: Law Enforcement • What can they do with this? • Correlate location, speed to independent identification? (cameras?) Photo Credit: Alex E. Proimos
  • 27. What you Can Do • Hack the radios • Commercially available now • Hack the protocols • Become politically engaged • Most decisions are not being made by elected officials • Help find a way to fund the infrastructure without selling out!
  • 29. Acknowledgements • Professor Dorothy Glancy, who requested my help on this project • DC 650 (especially Charles Blas) who gave me a reality check with current security and privacy capabilities
  • 30. Contact • Christie Dudley • @longobord • c.dudley@ieee.org

Notas do Editor

  1. Current law student. Privacy professor needed help
  2. should not matter But I’m working on that whole “lawyer” thing.
  3. little information to complete the audit. can talk about most published standards
  4. DSRC is a series of protocols. Has changed over the years of development. Black Hat talk: protocols are no longer relevant
  5. collision early warning system. - prevent accidents. - Save lives NHTSA “ distracted ” 2009 (US) stats: Almost 5,000 deaths, est 448,000 injuries Not including other inattention involving physical/emotional state of driver
  6. Good Work - want it to happen . Anecdote: driving in pouring rain too afraid to slow down, too afraid not to.
  7. Large scale testing in Ann Arbor Michigan started last August. Auto makers have already invested heavily in this technology. A few startups here in Silicon Valley to implement this.
  8. American government won’t spend money on infrastructure May be related to “black box” recent US mandate. Trucks have no privacy concerns as they are commercial vehicles.
  9. A system of protocols Not like asn.1 - not data pairs - Map of data
  10. Designed claimed as a “sealed” system, with sensor integrity and accuracy checks.
  11. Automakers lesson from CANbus: insecurity caused no real problems No new tech to mech tech - needs human intervention. “ sealed” sensor system with integrity checks.
  12. HOW it works
  13. Japan doesn’t have the same spectrum available ETSI and FCC approved operating parameters (Biggest difference: US allows more power.) 33 vs 44.7 dBm
  14. Minimum requirement for system. Additional protocols considered in Europe. illustrates general and some specific fields data = whatever’s useful in avoiding collisions
  15. More use = more effective People must trust the system Not just received, but what is sent about them Privacy is important or people will disable it Technological trust is better than laws
  16. Signature and certificate management - on radio Sensor validation (beyond scope here)
  17. Still not nailed down Ann Arbor test: came pre-loaded
  18. This is where we start talking about the FUD
  19. Already pressure for other apps - that need routing. Tension between routing and identifiability
  20. F/OSS Apps kind of neat. Closer to autonomy... Fun: someone in blind spot: “I wouldn’t do that, Dave” - give your vehicle too much power? This is too neat a toy to not use for other things.
  21. Permanent Blacklist? - may not be problem as internet - must replace entire blacklisted unit.
  22. Another problem for anonymity Many schemes to deal with this. Current solution is “no paper trail” We already have certain mistrust of CAs
  23. IEEE 1609 family beyond scope, won’t work - raises many more privacy concerns By the way 9 data brokers took the 5th before Congress in 2006 when asked to reveal the sources of their data.
  24. Tracking, ticketing, whatever else they may want to do.
  25. Fund certificate authority - funding has power.