A Runtime Decentralized Attestation and Coordinated Repair Framework for Securing Automotive ECUs

📅 2026-08-11
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
This work addresses the vulnerability of vehicle electronic control units (ECUs) to malware attacks and the challenge of achieving both efficient runtime detection and secure recovery with existing approaches. To this end, the paper proposes DACER, a novel framework that co-designs local firmware rollback with global ECU reboot mechanisms, leveraging the hierarchical nature of in-vehicle computing architectures to enable runtime recovery without single points of failure while meeting real-time constraints. Built upon ARM TrustZone and a secure flash memory controller, DACER supports per-ECU self-authentication, self-recovery, and low-overhead distributed coordination. Experimental evaluation on real hardware demonstrates that the framework efficiently performs whole-vehicle state verification and firmware restoration with minimal runtime overhead.
📝 Abstract
The evolution of automotive technology increasingly integrates components, transforming vehicles into interconnected systems of systems. Modern vehicles are controlled by a distributed system of computing devices, known as electronic control units (ECUs). However, this interconnectedness means that any error poses significant risks to the vehicle operator. In particular, malware can be injected into ECUs, threatening vehicle safety. To address this, we need mechanisms to detect compromised ECUs then repair them to a benign state. Existing approaches mainly focus on detection and do not address the challenge of integrating detection with runtime ECU repair. This integration is nontrivial because runtime repair involves both local rollback and reboot with timing determined from global vehicle context to avoid unsafe behavior. In this work, we have designed DACER, a runtime decentralized attestation and coordinated repair framework for automotive ECUs. DACER is the first approach that co-designs attestation and repair to unify the ``local'' nature of firmware rollback with the ``global'' nature of ECU reboot. In DACER, each ECU performs efficient local self-attestation and self-repair functions, enabling low-overhead coordination for distributed operations. In addition, DACER takes advantage of the hierarchical vehicle computing architecture. Our resulting DACER design checks the entire state of the vehicle, resists single points of failure, conforms to real-time constraints, and enables firmware restoration during runtime. The key functions are enabled by the ARM TrustZone equipped within each ECU and the secure flash memory controller embedded in the storage device. We implemented DACER on real-world hardware and experimentally demonstrated its low overhead.
Problem

Research questions and friction points this paper is trying to address.

automotive ECUs
malware
runtime repair
decentralized attestation
safety
Innovation

Methods, ideas, or system contributions that make the work stand out.

Decentralized Attestation
Coordinated Repair
Runtime Firmware Restoration
ARM TrustZone
Automotive ECUs
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
J
Josh Dafoe
Department of Computer Science, Michigan Technological University, Houghton, Michigan, USA
N
Niusen Chen
Department of Computer Science and Engineering, University of Nevada, Reno, Reno, Nevada, USA
Bo Chen
Bo Chen
Associate Professor of Computer Science, Michigan Technological University
Applied CryptographyData SecurityMobile Devices/IoT/CPS SecurityCloud Security