SAE J3101_202002 PDF | Request Standard
Historical

SAE J3101_202002

Hardware Protected Security for Ground Vehicles

Standard by SAE International, 2020-02-10

Available Formats:

  • Availability: Immediate Download
  • Language: English
  • License Type: Single User
  • Updates: Not Included
  • Availability: Request Quote
  • Language: English
  • License Type: Enterprise / Multi User
  • Updates: Included

About This Item

Access mechanisms to system data and/or control is a primary use case of the hardware protected security environment (hardware protected security environment) during different uses and stages of the system. The hardware protected security environment acts as a gatekeeper for these use cases and not necessarily as the executor of the function. This section is a generalization of such use cases in an attempt to extract common requirements for the hardware protected security environment that enable it to be a gatekeeper. Examples are: Creating a new key fob Re-flashing ECU firmware Reading/exporting PII out of the ECU Using a subscription-based feature Performing some service on an ECU Transferring ownership of the vehicle Some of these examples are discussed later in this section and some have detailed sections of their own. This list is by no means comprehensive. Other use cases that require hardware protected security environment-based access control may be used by each manufacturer/service provider based on vehicle capabilities, architecture, and business model. This section describes how the hardware protected security environment provides a platform to implement access control by enabling secure authentication, authorization and access enforcement. It does not define any specific access control system (DAC/MAC/capability-based/role-based/etc.), models, or polices. A general access control system is based on the following stages: 1 Identifying and authenticating the user. 2 Authorizing access to the resource. a Comparing authenticated user to policies (database/certificates/other). b Comparing other conditions (temporal/spatial/other) to policies database. c Unlocking access to the resource. 3 Using the resource. 4 (Optional) Removing access to the resource based on temporal or other conditions. a Locking access to the resource. The hardware protected security environment can be involved to different extents in each of the stages listed above. The main two types of hardware protected security environment involvements are full control and partial control. In partial control, the hardware protected security environment is responsible to authenticate and authorize the access, while the normal environment is responsible to lock/unlock the resource. In full control, the hardware protected security environment is responsible for both. Automotive computer systems are required to establish trustworthiness through device identity, sealing, attestation, data integrity, and availability. These systems must be resilient to a wide range of attacks that cannot be thwarted through software-only security mechanisms. A hardware root of trust and the hardware-based security primitives are fundamentally necessary to satisfy demands of connected and highly or fully automated vehicles. This document provides a comprehensive view of security mechanisms supported in hardware for automotive use cases, along with best practices for using such mechanisms.
SKU: a72824c9f71b

  • Publication Date: 2020-02-10
  • Standard Status: latest
  • Publisher: SAE International
  • Document Type: Ground Vehicle Standard
  • Subject: Cybersecurity, Terminology, Vehicle to vehicle (V2V), Engine control systems, Supply chain management, Computer privacy, Cryptography, Failure modes and effects analysis, End-of-life vehicles
  • Official SAE: Doi link

Please request information about the document. Contact Page

Online Standart App

Need This Standard?

Need This Standard?

Summarize with AI

ChatGPT Perplexity Google AI Claude Grok

Online Standart Disclaimer

OnlineStandart.com is an authorized reseller of international standards, operating through partnerships with authorized distributors. We do not own the copyrights or trademarks of the standards we sell, including but not limited to those of API, ASHRAE, BSI, SAE, ASTM, IEEE, IEC, ASME, ISO, and others.

All product names, logos, and brands are the property of their respective owners and are used for identification purposes only; their use does not imply endorsement. OnlineStandart.com is not affiliated with or endorsed by any standards development organization unless explicitly stated. The content of this document is for informational purposes only and is intended to promote our licensed reselling services.

Online Standart does not host, distribute, or link to free, unlicensed, or uncertified copies of copyrighted standards. Every document we deliver is a licensed copy obtained through authorized channels and supplied with full licensing documentation. The “Free PDF Download” option on our product pages refers to this free informational document — never to a free copy of any standard.