Browse Publications Technical Papers 11-02-02-0008
2020-08-13

Secure Boot Revisited: Challenges for Secure Implementations in the Automotive Domain 11-02-02-0008

This also appears in SAE International Journal of Transportation Cybersecurity and Privacy-V128-11EJ

Secure boot, although known for more than 20 years, frequent attacks from hackers that show numerous ways to bypass the security mechanism, including electronic control units (ECUs) of the automotive industry. This paper investigates the major causes of security weaknesses of secure boot implementations. Based on penetration test experiences, we start from an attacker’s perspective to identify and outline common implementation weaknesses. Then, from a Tier-One perspective, we analyze challenges in the research and development process of ECUs between original equipment manufacturers (OEMs) and suppliers that amplify the probability of such weakness. The paper provides recommendations to increase the understanding of implementing secure boot securely on both sides and derives a set of reference requirements as a starting point for secure boot ECU requirements.

SAE MOBILUS

Subscribers can view annotate, and download all of SAE's content. Learn More »

Access SAE MOBILUS »

Members save up to 19% off list price.
Login to see discount.
We also recommend:
TECHNICAL PAPER

Test Method for the SAE J3138 Automotive Cyber Security Standard

2020-01-0142

View Details

TECHNICAL PAPER

Model-Based Software Development: Functional Safety Compliance via Built-In Tool Intelligence

2019-01-1041

View Details

TECHNICAL PAPER

Tool Integration from Design to Test

2003-01-1204

View Details

X