Authorization Framework for Secure Cloud Assisted Connected Cars








- Slides: 8
Authorization Framework for Secure Cloud Assisted Connected Cars and Vehicular Internet of Things Maanak Gupta and Ravi Sandhu Institute for Cyber Security, Center for Security and Privacy Enhanced Cloud Computing, Department of Computer Science University of Texas at San Antonio 23 rd ACM Symposium on Access Control Models and Technologies (SACMAT 2018) Indianapolis, IN, USA, June 13 -15, 2018 © Maanak Gupta World Leading Research with Real World Impact!
Connected Cars Ecosystem © Maanak Gupta World Leading Research with Real World Impact! 2
Security and Privacy Requirements Ø On-Board Application and Sensors • Tesla and Jeep X Ø Over the Air updates Ø V 2 X fake messages Ø In-vehicle ECU communication Ø Personal Data Ø Third Party devices Ø User Privacy Preferences Ø Spoofing, Ransomware, Injection… Ø Loss of Information in Cloud © Maanak Gupta World Leading Research with Real World Impact! 3
Security and Privacy Requirements Ø On-Board Application and Sensors • Tesla and Jeep X Ø Over the Air updates Ø V 2 X fake messages Ø In-vehicle ECU communication Ø Personal Data Ø Third Party devices Ø User Privacy Preferences Ø Spoofing, Ransomware, Injection… Ø Loss of Information in Cloud © Maanak Gupta World Leading Research with Real World Impact! 4 - Software Reliance - Broad Attack Surface - Untrusted Entities
Extended Access Control Oriented Architecture © Maanak Gupta World Leading Research with Real World Impact! 5
Authorization Framework © Maanak Gupta World Leading Research with Real World Impact! 6
Access Control Strategies Ø Static vs Dynamic Ø What kind of relationship they have? • Owner • Manufacturer • Friend Ø Multi-Layered Ø Groups Based Ø Trusted Interaction • How I trust you? • Previous interaction. . ? Ø ABAC, Re. BAC Models Ø Who will administer ? Ø Data in Cloud, cross cloud sharing, how? © Maanak Gupta World Leading Research with Real World Impact! 7
Research Questions Ø External Interface Ø In-Vehicle Interaction Ø Whom to TRUST? How establish TRUST? Ø Cross Cloud Sharing Ø Data in Cloud © Maanak Gupta World Leading Research with Real World Impact! 8