IMCS Lab

Research

Securing intelligent mobility โ€” from regulation and risk assessment to in-vehicle intrusion detection and EV charging authentication.

Motivation

Connected-car hacking and fatal crashes in driving automation changed the automotive security paradigm: attacks arrive over wireless networks, target unspecified vehicles, reach safety functions directly, and place responsibility on manufacturers.

Connected-car hacking: the Jeep Cherokee remote hack
Connected-car hacking โ€” the Jeep Cherokee hack (C. Miller and C. Valasek, Black Hat 2015)
Fatal crash in driving automation
Fatal crash in driving automation โ€” the Autopilot accident (Florida, May 2016)

Automotive cybersecurity

Cybersecurity management systems, UN R.155 and ISO/SAE 21434

Laws and regulations for automobiles now require the reinforcement of security as well as safety, which reshapes how manufacturers build and certify vehicles.

Automotive regulations for safety and security
Automotive regulations for safety and security

TARA and the PIER method for cybersecurity risk assessment

The PIER approach considers cyber-resilience: beyond the risk factors of probability and impact, it also covers exposure and recovery. See Projects for details.

The PIER method for TARA
The PIER method for TARA

In-vehicle IDS and remote analysis

  • Automotive intrusion detection based on message and state learning in the in-vehicle network
  • Avoiding the classification of data that will not be used, via a hierarchical multi-class model
Intrusion detection for the in-vehicle network
Intrusion detection for the in-vehicle network
Hierarchical multi-labeled classification method for intrusion detection
Hierarchical multi-labeled classification for intrusion detection

Plug and Charge and ISO 15118

Authentication and automatic payment for electric vehicle charging, built on a public key infrastructure. See Projects for details.

Plug and Charge based on ISO 15118
Plug and Charge based on ISO 15118

Automotive OTA software update

Integrity validation of ECU software to prevent manipulated code injection attacks.

Automotive software update Over-The-Air
Automotive software update Over-The-Air (OTA)

Auto-ISAC council

Enhancing cybersecurity and sharing information on cyber threats and vulnerabilities among automotive industry members and the US government since 2015. Auto-ISAC promotes collaboration and coordination among its members, such as vehicle manufacturers, suppliers and automotive cybersecurity professionals.

The Auto-ISAC council
The Auto-ISAC council

Fundamental technology for autonomous vehicles

Perception

Recognizing moving objects from multiple sensing data fusion, including adaptive point cloud processing for perceptual quality.

Planning

Trajectory planning that predicts the movement and interference of moving objects for collision avoidance.

Software update

Automotive OTA update mechanisms aligned with UN R.156 and ISO 24089.