Return
CROSS-TEE: A Distributed Trusted Execution Environment Architecture for Cross-Module Automotive Security
S
K
H
S
K
DOI:10.1109/tifs.2026.3714115.png)
Abstract
En 中文
The rapid development of intelligent, connected, and electrified automotive technologies has significantly enhanced convenience, driving substantial growth in the intelligent connected vehicle (ICV) market, and accelerating the replacement of traditional fuel-powered vehicles. However, these advancements have introduced new attack surfaces, giving rise to emerging security threats such as malicious injection attacks on the controller area network (CAN) bus and eavesdropping attacks on in-vehicle Ethernet communications. Existing security solutions face limitations such as lack of holistic defense, insufficient application isolation, absence of security checks for CAN bus invocation requests, and plaintext Ethernet data transmission, which undermine ICV security. To address these problems, we propose CROSS-TEE, the first cross-module distributed customizable trusted execution environment (TEE) architecture designed to manage the interaction between different system modules (e.g., domain controller, central gateway, etc.) in vehicles. CROSS-TEE consists of two levels: one type of Level-1 TEE and three types of Level-2 TEEs, tailored to different application and security requirements. We design a trusted house mechanism to isolate trusted applications (TAs) and a pre-transmission protocol to enable secure data transmission. CROSS-TEE only allows direct CAN bus invocation requests from TAs, while requiring similar requests from applications in the normal world to pass security checks by either secure monitor (SM) or trusted operating system (OS) before approving them. The prototype of CROSS-TEE is built using Renesas RA6M5 and Raspberry Pi 3 Model B development boards. Experimental results demonstrate the effectiveness of CROSS-TEE’s security mechanisms against remote attacks (e.g., arbitrary CAN bus message injections, unauthorized invocations of security-critical applications, and malicious access to in-vehicle Ethernet networks), with average time overheads of approximately 7.8% for CAN bus communication and <inline-formula xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink"> <tex-math notation="LaTeX">$1.73\times $ </tex-math></inline-formula> for encrypted Ethernet communication, indicating an acceptable security-performance trade-off.
Keywords:
Trusted execution environment
automotive security
CAN bus access control
in-vehicle Ethernet security
remote attack mitigation
Journal
IF:
8
Papers:
5.2K
Citations:
2.3W
