本报告主要对智能网联汽车在网络安全与数据安全方面的数字密钥行业发展进行分析。首先分析了数字密钥行业发展情况。从遥控密钥行业发展历程切入,由于近年来智能手机的普及,数字密钥行业发展较快。其次阐述了数字密钥行业发展趋势,主要介绍了应用蓝牙传输技术的优势与未来应用场景。数字钥匙同样存在安全风险——近场通信安全风险、移动App安全风险、4G/5G威胁风险等。最后探讨了数字钥匙行业中的安全案例,有本田思域钥匙攻击——滚动码的同步计数器可以回滚造成过期开门指令可以恢复使用,以及特斯拉数字钥匙攻击——相关安全研究人员发现在TeslaModelS的PKES系统,挑战响应认证协议会因非常小的密钥空间和弱的双向认证方式而可能被攻击,盗贼可通过中继攻击盗取车辆贵重物品。
<<This section will mainly analyze the development of digital key industry in network security and data security of Intelligent Connected Vehicles(ICVs). Firstly,this section introduces the basic situation of digital key. Starting from the development process of remote key,due to the development and popularity of smart phones in recent years,it is becoming a natural development trend of digital key. Then it describes the development trend of digital key,mainly introduces the advantages of Bluetooth transmission technology and future application scenarios. Digital keys also have security risks:near-field communication security risk,mobile APP security risk,4G/5G threat risk,etc. Finally,several security cases of digital keys are introduced. There are Honda Civic key attack,in which the synchronous counter of the rolling code can be rolled back to cause the expired open door command can be restored,Tesla digital key attack,in which the relevant security researchers found that the PKES system of Tesla Model S,The Challenge Response Authentication Protocol can be attacked due to its very small key space and weak two-way authentication,and thieves can steal vehicle valuables through relay attacks.
<<