精品日韩中文字幕_日韩精品在线观看视频_中文字幕一区二区在线观看_欧美高清视频一二三区

Digital car keys raise security concerns

來(lái)源: | 2023-06-08 10:48:37
Drivers can store automotive digital keys on their smartphones, smartwatches and other connected devices, allowing them to unlock and start their cars with just a tap or a swipe. Digital keys also let...

Drivers can store automotive digital keys on their smartphones, smartwatches and other connected devices, allowing them to unlock and start their cars with just a tap or a swipe. Digital keys also let owners control the amount of time a user can drive a car, set minimum and maximum speeds, and limit access to certain parts of the vehicle.

Most drivers who use mobile phones to access and start their vehicles say they like the convenience of the apps but still worry about security, according to the Car Connectivity Consortium.

"The keys are exploitable," said Jason Kent, a "hacker in residence" at Cequence Security, a cybersecurity firm in Sunnyvale, Calif.

The consortium, which watches the issues and sets standards for digital key systems, has 200 members and includes most automakers. It is looking to "future-proof vehicle access using smart devices."

The consortium's charter members are Apple, BMW, Denso, Ford, General Motors, Google, Honda, Hyundai, Mercedes-Benz, NXP, Panasonic, Samsung, Thales, Xiaomi and Volkswagen.

Most automotive digital key technology relies on near-field communication and Bluetooth low-energy technology.

"It's a very mature technology, so there is no way to get to the keys unless you are a government or an agency like the CIA," said Michael Leitner, senior director of smart car access at chipmaker NXP and vice president of communications at the Car Connectivity Consortium.

The software and safeguards for automotive digital keys have advanced so much that it's a very time-intensive and arduous effort to hack the technology, Leitner said.

"I think the Car Connectivity Consortium has produced a good piece of work: the concepts for key management offer some really useful functionality, and address a number of issues around vehicle key security," said Ken Tindell, co-founder of Canis Automotive Labs, a U.K. automotive and aerospace security technology firm.

However, automotive cybersecurity experts are still determining if digital keys are as secure as the industry claims.

Kent said a rash of recent car thefts in the U.K. targeting new cars with keyless systems that were hacked using relay attacks or "key cloning" demonstrates how the industry underestimates vehicle security.

Automakers have responded to key cloning attacks with keys that go into sleep mode. Vehicle owners have attempted a different strategy, such as keeping keys in a metal container like coffee cans or breath mint tins.

The Kia Boy attacks, which involve thieves popping off the steering wheel column of key ignition in Hyundai and Kia models and using a USB to hot-wire them, offer another example.

Kia and Hyundai — sibling companies — issued a software update to fix the problem, but Automotive News reported Hyundai Motor Group's solution is not working perfectly.

"It's not feasible or realistic to attack this key security head-on," Tindell said.

Car thieves are moving on from key cloning because automakers such as Toyota are placing robust encryption systems between its keys and the smart key electronic control unit, a dedicated chip with software or firmware that controls security and access in its vehicles to authenticate the key, Tindell said.

He likened the hacks and countermeasures between car thieves, hackers and automakers to an arms race.

Car thieves, for example, are developing an attack method called a controller area network injection, Tindell said. The CAN injection circumvents standard antitheft equipment by going around the back.

Car thieves and hackers must physically break into the internal network of a car, which they can do if it is somewhere easy to reach on the vehicle, Tindell said.

In a blog post, Tindell unwrapped how car thieves in the U.K. stole a Toyota RAV4 from Ian Tabor, a cybersecurity researcher and automotive engineering consultant for Switzerland's EDAG Engineering Group.

Thieves broke into the RAV4's CAN near the headlights to access its key security's ECU for its engine and doors.

"In some ways, it's like a castle with a drawbridge and portcullis and a barbican to secure the front entrance, and an unguarded back door with a cheap padlock," Tindell said.

Automakers need to have authentication and encryption for the digital messaging between a car's door and engine to defeat these CAN injection attacks, Tindell said. They need some sort of credential or token system.

"Having your phone say, 'Are you trying to open the car' is probably too much, but it's leaning toward the direction I think it will go," Kent said.

Because the cars were physically broken into, the CAN attack on Tabor's RAV4 and the Kia Boys hacks created extra risk for the perpetrators. Still, car hacking could become easier as more drivers adopt digital keys.

Determined hackers will eventually find a direct or indirect way into guarded technology, said a white hat hacker well-known in security circles who goes by the name of Sick Codes.
"Nothing is unhackable," he told Automotive News.

In the coming years, a digital key could be hacked from the backend or a server, Codes said.

Besides not requiring drivers to put a key in an ignition, Codes doesn't think there's much of a benefit to automotive digital keys. He said they are little more than a data play by automakers to create additional revenue streams.

"It looks good on paper. If it's done well, it might work, but as we know, little to never of anything (software) is done very well," Codes said. "I think it's a disaster waiting to happen."

相關(guān)熱詞搜索:

上一篇:豪華越野可以兼得,探險(xiǎn)者昆侖巔峰版才是一步到位的穿越神器
下一篇:2023西點(diǎn)汽車總評(píng)榜,看中國(guó)車市的智變趨勢(shì):創(chuàng)新求變,還是降價(jià)競(jìng)爭(zhēng)?

主站蜘蛛池模板: 国产狼人综合免费视频| 日韩精品一区二区三区四| 国产精品久在线观看| 91av在线国产| 男女视频一区二区三区| 91国产在线精品| 国产精品中文字幕久久久| 日本一区免费在线观看| 国产mv久久久| 国产视频99| 狠狠干视频网站| 欧美精品一区三区在线观看| 国产精品老女人精品视频| 国产在线一区二区三区播放| 欧美视频在线第一页| 日韩欧美视频第二区| 亚洲在线欧美| 99视频在线| 国产超级av在线| 国产精品国模在线| 国产精品久久在线观看| 国产欧亚日韩视频| 国产一区二区在线免费| 九九热精品视频| 久久久精品视频在线观看| 久久天天狠狠| 久久久久中文字幕| 久久久久国色av免费观看性色| 久久久久久成人精品| 久久国产精品99国产精| 九九精品在线观看| 国产精品亚发布| 高清国产一区| 在线国产99| 日韩视频在线观看国产| 日韩国产精品毛片| 欧美精品尤物在线| 国产在线视频91| 国产成人亚洲综合青青 | 日本丰满少妇黄大片在线观看| www..com日韩|