Blind Wireless Seed Key Exchange
Heavy vehicle tanker trailers utilize the PLC4TRUCKS (ISO 11992-3) power line communication databus, which incorporates wirelessly accessible interfaces. Electronic Control Units (ECUs) on this bus often employ the KWP2000 (ISO 14230) diagnostic protocol, secured by a seed-key authentication mechanism intended to prevent unauthorized access. This paper presents a security analysis of this implementation. We demonstrate significant predictability in the seed generation algorithm employed by trailer ECUs. Exploiting this weakness, we developed and experimentally validated a novel timing-based reset attack capable of bypassing the KWP2000 seed-key security. Notably, this attack enables unauthorized diagnostic access without requiring observation of ECU responses (blind attack) and can be initiated non-contact via the wireless interface. Our findings confirm these vulnerabilities extend to contemporary trailer brake control systems, highlighting a persistent risk. We conclude that tractor units require enhanced security measures to mitigate such wireless threats against connected trailer systems.
About the Speaker:
Anne Zachos is a Cybersecurity Research Engineer at the National Motor Freight Traffic Association, Inc. (NMFTA)™.
Anne has a strong background in embedded systems engineering and is dedicated to advancing cybersecurity within the trucking industry. Her work is centered on securing connected vehicle technologies, focusing on both the technical challenges of embedded firmware and the broader cybersecurity threats facing commercial transportation. Anne contributes to several American Trucking Association (ATA) TMC task forces as well as technical standards committees under SAE International. At NMFTA, Anne contributes both to research initiatives and educational efforts, helping to strengthen the industry's overall cybersecurity posture and awareness.
Видео Blind Wireless Seed Key Exchange канала SecureOurStreets
About the Speaker:
Anne Zachos is a Cybersecurity Research Engineer at the National Motor Freight Traffic Association, Inc. (NMFTA)™.
Anne has a strong background in embedded systems engineering and is dedicated to advancing cybersecurity within the trucking industry. Her work is centered on securing connected vehicle technologies, focusing on both the technical challenges of embedded firmware and the broader cybersecurity threats facing commercial transportation. Anne contributes to several American Trucking Association (ATA) TMC task forces as well as technical standards committees under SAE International. At NMFTA, Anne contributes both to research initiatives and educational efforts, helping to strengthen the industry's overall cybersecurity posture and awareness.
Видео Blind Wireless Seed Key Exchange канала SecureOurStreets
Комментарии отсутствуют
Информация о видео
25 сентября 2025 г. 19:56:36
00:35:52
Другие видео канала