A safe dynamic access control providing mandatory automotive cybersecurity

The recent computerization of automotive vehicles offers new ways for attackers to penetrate critical systems. To ensure their safety, cybersecurity is therefore required. Cyberse-curity can be enforced with different mechanisms, such as access control, thanks to reference monitors. However, systematic access control may harm safety properties in certain scenarios. Therefore, the integration of access control mechanisms in automotive systems remains an open problem. Our paper provides a general approach adding dynamic mandatory access control to enforce security properties while guaranteeing their innocuousness with respect to the vehicle’s safety. To achieve this, we start by formally modeling the system. Then, a mandatory access control policy is proposed with respect to the different vehicle’s states. Using a dedicated model checking tool, the safety of the access control mechanism is verified with respect to a formal attack model. Using the attack paths produced by the verification tool, the access control policy can be iteratively refined, thus improving the availability and resilience of the system.

Paper

Full text

PDF

A safe dynamic access control providing mandatory automotive cybersecurity

Semantic Scholar · Computer Science · 2021

Abstract

The recent computerization of automotive vehicles offers new ways for attackers to penetrate critical systems. To ensure their safety, cybersecurity is therefore required. Cyberse-curity can be enforced with different mechanisms, such as access control, thanks to reference monitors. However, systematic access control may harm safety properties in certain scenarios. Therefore, the integration of access control mechanisms in automotive systems remains an open problem. Our paper provides a general approach adding dynamic mandatory access control to enforce security properties while guaranteeing their innocuousness with respect to the vehicle’s safety. To achieve this, we start by formally modeling the system. Then, a mandatory access control policy is proposed with respect to the different vehicle’s states. Using a dedicated model checking tool, the safety of the access control mechanism is verified with respect to a formal attack model. Using the attack paths produced by the verification tool, the access control policy can be iteratively refined, thus improving the availability and resilience of the system.

Similar papers

© 2026 NYSGPT2525 LLC