Re: Connected Cars. Upgradable/Replaceable IoT systems. Re: Managing Long-Lived CA certs

Erwann Abalea <[email protected]>
Newsgroups gmane.ietf.x509
Message-ID <CA+i=0E7EzUeUcEAONCo6dXOOtg4DF0oAg9pRupTzcw_X47vgsQ@mail.gmail.com>
2017-07-24 15:23 GMT+02:00 Robert Moskowitz <[email protected]>:

> I have consulted a few auto OEMs on matters like this.
>
> Today, and actually for a few years, all devices with software MUST be
> field (minimum dealer) upgradeable.  And some support 'over the air'
> updates.
>
> This includes the 'telematics' control unit where up to now, has been the
> only component with certificates.  I worked on three telematics certificate
> systems.
>
> The IEEE 1609.2 standard for Vehicle safety messaging has a 'monster' PKI
> with certificate management.  To put it mildly.
>
> However, IEEE 802.1AR 'Device Identity' standard defines the iDevID as a
> permanent, non-mutable certificate with expected 10 - 20 year life.  Yeah
> lots of issues with this.  Lots of reasons for this approach.  Note that
> the iDevID is only used for proof on manufacturer identity when enrolling
> in the buyer's PKI with the lDevID (see ANIMA that is using these).   It
> may also be used in firmware updates from the manufacturer.  Thus the
> iDevID is not intended to be an 'operational' certifcate.
>

That's right. This long-term ID is used to get short-term IDs that are
changed frequently and used to sign messages (CAM and DENM at least).

Having worked on the ETSI counterpart of 1609.2, the expected figures are:
around 1500 short-term IDs per vehicle and per year, CAMs are to be
sent+signed between 1 and 10 times per second (depending on environment and
network status).

ETSI also wanted to have their own autoconfigurable network, in which
network addresses contain GPS coordinates, some messages specify the
intended network coverage, and every vehicle can act as a mobile router.
And all messages are to be signed, by one of these short-term IDs.

Reason for a new certificate format: reduce the size of network packets to
limit the congestion; ETSI adds a congestion control layer that doesn't
exist in 1609.x, limiting in-air messages to 0.6s, whatever the current
rate (which is also negotiable).
Reason for that many certificates: try to forbid an attacker to passively
track a vehicle's path. Privacy, in fact.

Revocation of these short-term IDs is somewhat defined in 1609.2, not at
all in ETSI (that may change).

-- 
Erwann.

_______________________________________________
pkix mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/pkix
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.