Daniel Zelle

dblp:196/5989 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
3since 2021 · last 2022
0000-0001-5448-5152ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 2 since 2021
YearPublicationVenuePosition
2022 Local Power Grids at Risk - An Experimental and Simulation-based Analysis of Attacks on Vehicle-To-Grid Communication
abstract
With Electric Vehicles (EVs) becoming more prevalent, their battery recharge creates significant loads on power grids. Especially in local grids with a high share of households that own an EV, this additional energy demand can stress existing power distribution systems that were not designed for this kind of loads. The unexpected peak consumption may reduce service quality, damage sensitive equipment, cause power failures and even local blackouts. To mitigate this risk, grid components must be either significantly upgraded to match the increased demand, or the demand must be managed to avoid critical situations. Vehicle-to-Grid (V2G) technology is a major emerging trend for enabling load management in connection with EV charging. A key component of V2G is the ISO 15118 protocol allowing to set grid-friendly charging schedules for EVs. This standard is further supported by backend protocols like OCPP to permit corrective actions by a network operator.
Maria Zhdanova, Julian Urbansky, Anne Hagemeier, Daniel Zelle, Isabelle Herrmann, Dorian Höffner
ACSAC4
2021 Analyzing and Securing SOME/IP Automotive Services with Formal and Practical Methods
abstract
Automotive Ethernet is increasingly used in modern vehicles and complements or replaces legacy bus systems such as CAN. Ethernet also enables service-oriented communication with the Scalable service-Oriented MiddlewarE over IP (SOME/IP) middleware. In this paper, we present a formal and practical security analysis of Scalable service-Oriented MiddlewarE over IP (SOME/IP), the identified Man-in-the-Middle (MITM) attacks, and propose two security extensions. The attacks are possible even if SOME/IP is used in combination with link layer security mechanisms. The attacker can impersonate a service offering server and a service consuming client. The two most common communication methods, request/response and publish/subscribe, are both vulnerable. In most communication scenarios, we are able to route all messages over the attacker. Our security extensions for authentication and authorization of service provisioning and usage protect against these attacks. We formally analyze the security and evaluate the overhead with practical implementations.
Daniel Zelle, Timm Lauser, Dustin Kern, Christoph Krauß
ARES1
2021 Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
abstract
Connected smart cars enable new attacks that may have serious consequences. Thus, the development of new cars must follow a cybersecurity engineering process as defined for example in ISO/SAE 21434. A central part of such a process is the threat and risk assessment including an attack feasibility rating. In this paper, we present an attack surface assessment with focus on the attack feasibility rating compliant to ISO/SAE 21434. We introduce a reference architecture with assets constituting the attack surface, the attack feasibility rating for these assets, and the application of this rating on typical use cases. The attack feasibility rating assigns attacks and assets to an evaluation of the attacker dimensions such as the required knowledge and the feasibility of attacks derived from it. Our application of sample use cases shows how this rating can be used to assess the feasibility of an entire attack path. The attack feasibility rating can be used as a building block in a threat and risk assessment according to ISO/SAE 21434.
Christian Plappert, Daniel Zelle, Henry Gadacz, Roland Rieke, Dirk Scheuermann, Christoph Krauß
PDP2
2020 SEPAD - Security Evaluation Platform for Autonomous Driving
abstract
The development and evaluation of security solutions for autonomous vehicles is a challenging task. Many researchers have no access to real vehicles to implement and test their solutions. In addition, vehicle E/E architectures of different brands or even model series of one car manufacturer differ significantly. Also, vehicles may be the source of physical hazards, e.g., an exploding airbag. To enable researchers to develop, implement, and evaluate new security solutions for autonomous vehicles, we propose a new security evaluation platform called SEPAD and a dedicated development process for testing security mechanisms with it. SEPAD allows to model realistic E/E architectures where the developed security solutions can be integrated and evaluated without causing safety risks for the researcher or other road users.
Daniel Zelle, Roland Rieke, Christian Plappert, Christoph Krauß, Dmitry Levshun, Andrey Chechulin
PDP1
2018 The user-centered privacy-aware control system PRICON: An interdisciplinary evaluation
abstract
The advent of connected vehicles has increased the relevance of privacy in cars. While current approaches to increase security and privacy in connected vehicles are mainly driven from technological perspectives, users do not have active control over their personal data. Therefore, the user-centered privacy-aware control system PrivacyController (PRICON) has been developed which incorporates expertise from judicial, technical and user-centered perspectives. PRICON provides users with a user-friendly possibility to define self-determined privacy policies which are applied to the vehicular system. In this paper, we report the evaluation of PRICON from a legal, technical and user-centered point-of-view. The evaluation results are discussed and practical implications are derived.
Jonas Walter, Bettina Abendroth, Thilo Von Pape, Christian Plappert, Daniel Zelle, Christoph Krauß, G. Gagzow, Hendrik Decke
ARES5
2018 Anonymous Charging and Billing of Electric Vehicles
abstract
None of the existing and upcoming Plug-and-Charge (PnC) related standards define privacy-preserving measures for protecting privacy-sensitive charging and billing data to prevent attacks such as the generation of movement profiles. To address this issue, we analyze PnC protocols with respect to privacy, identify requirements for privacy-preserving PnC solutions, and propose a PnC protocol extension enabling users to charge Electric Vehicle (EV) anonymously and service providers to securely bill their customers. Our approach addresses the complete PnC process chain and is based on a Direct Anonymous Attestation (DAA) protocol using a Trusted Platform Module (TPM) in the vehicle. Our analysis shows that our approach effectively protects the customers privacy while introducing only minimal additional protocol overhead.
Daniel Zelle, Markus Springer, Maria Zhdanova, Christoph Krauß
ARES1
2017 On Using TLS to Secure In-Vehicle Networks
abstract
A trend in modern in-vehicle networks is the use of network technologies with higher bandwidth such as Automotive Ethernet. As a result, more sophisticated security technologies may be used to secure the communication. In this paper, we investigate whether the Transport Layer Security Protocol (TLS) is applicable to secure in-vehicle networks. First, we identify the security and performance requirements as well as the communication scenarios which must be supported by the TLS communication. Next, we discuss how these requirements can be realized with TLS. This also includes the discussion of the certificate management. Finally, we present and discuss our prototypical TLS implementation on a typical automotive platform and show that TLS is able to fulfill most performance requirements of the automotive industry.
Daniel Zelle, Christoph Krauß, Hubert Strauß, Karsten Schmidt 0003
ARES1
2017 Behavior Analysis for Safety and Security in Automotive Systems
abstract
The connection of automotive systems with other systems such as road-side units, other vehicles, and various servers in the Internet opens up new ways for attackers to remotely access safety relevant subsystems within connected cars. The security of connected cars and the whole vehicular ecosystem is thus of utmost importance for consumer trust and acceptance of this emerging technology. This paper describes an approach for on-board detection of unanticipated sequences of events in order to identify suspicious activities. The results show that this approach is fast enough for in-vehicle application at runtime. Several behavior models and synchronization strategies are analyzed in order to narrow down suspicious sequences of events to be sent in a privacy respecting way to a global security operations center for further in-depth analysis.
Roland Rieke, Marc Seidemann, Elise Kengni Talla, Daniel Zelle, Bernhard Seeger
PDP4