Intra-Vehicle Information Security Framework

This paper presents an internal information security services framework for vehicular environments. The framework consists of a logical toolbox — a set of logical modules that are installed in a variety of embodiments (e.g., controllers) and which provide security functionality that vehicular applications require. The framework also includes several enablers, which are higher-level security functions that are integrated into vehicular applications. These enablers use the aforementioned tools to provide for many typical use-cases, such as secure logging, secure code update, and secure feature activation. The purpose of the toolbox is to provide some of the common security functions at the highest effective abstraction level, and to implement these functions securely in well suited embodiments. This detachment of security functions from the applications that use them shall allow developers to develop secure applications without requiring extensive security know-how, as well as to reduce the attack surface of their applications.