Christian Plappert

dblp:196/8840 · DBLP profile ↗
← Back
16ranked-venue papers
10as first author
13since 2021 · last 2026
0000-0001-7404-5349ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 7 first-author · 8 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Missing the Link? Enhancing the Security of Digital Car Keys With Secure Session Linking and Hardware Trust
Christian Plappert, Daniel Trick
ACISP (1)1
2026 A Survey of AI Applications and Their Security Challenges for Autonomous Driving
Leon Ramirez, Marco Leeske, Christian Plappert
VEHITS3
2026 Automotive Security Architectures for Plug & Charge with a Central Trusted Platform Module
abstract
244
Stephan Zitzlsperger, Mahboubeh Tajmirriahi, Abhishek Subedi, Simon Rudhart, Daniel Trick, Martin Schramm, Christian Plappert
VEHITS7
2024 Hardware Trust Anchor Authentication for Updatable IoT Devices
abstract
Secure firmware update mechanisms and Hardware Trust Anchors (HTAs) are crucial in securing future IoT networks. Among others, HTAs can be used to shield security-sensitive data like cryptographic keys from unauthorized access, using hardware isolation. Authentication mechanisms for key usage, however, are difficult to implement since corresponding credentials need to be stored outside the HTA. This makes them vulnerable against host hijacking attacks, which in the end also undermines the security gains of the HTA deployment.
Dominik Lorych, Christian Plappert
ARES2
2023 Secure Multi-User Contract Certificate Management for ISO 15118-20 Using Hardware Identities
abstract
In recent years, traditional mobility concepts have been increasingly transformed in favor of electric mobility and vehicle sharing concepts to combat pollutant emissions and inner-city traffic congestion. While the electric charging standard ISO 15118 with its Plug&Charge (PnC) concept eases the user experience by handling the complex billing process automatically during the charging, it is currently not suitable to the new multi-user mobility concepts since it does not define how to handle charging identities for multiple users per vehicle. With the Trusted Platform Module (TPM) 2.0 already part of the current ISO 15118-20 standard, we propose a new secure and standard-compliant multi-user contract certificate management system for ISO 15118-20 that utilizes the TPM in the vehicle as hardware trust anchor to handle multiple vehicle users. Our concept has little overhead to the current standard and introduces secure TPM-based multifactor authentication into ISO 15118-20, while maintaining the convenience benefits of PnC.
Christian Plappert, Lukas Jäger, Alexander Irrgang, Chandrasekhar Potluri
ARES1
2023 Secure and Lightweight Over-the-Air Software Update Distribution for Connected Vehicles
abstract
Connected vehicles are increasingly threatened by cyberattacks during their long lifecycle. Therefore, timely Over-the-Air (OTA) update processes are becoming a mandatory mitigation mechanism and their security a critical task. In this paper, we present a novel secure OTA update distribution mechanism for connected vehicles that addresses threats and requirements of recent automotive security regulations and standards. We tailor our security concept to the capabilities of a Trusted Platform Module 2.0 (TPM) that we deploy as hardware trust anchor at the vehicle telematics unit and show its benefits and uniqueness regarding security guarantees and functionality in comparison to related work. In our concept, the TPM acts as trusted update distribution point that securely translates the asymmetric backend cryptography to the symmetric in-vehicle cryptography and as update authorization point that coordinates the update installation, e.g., regarding the vehicle state. These concepts are completely enforced inside the shielded location of the TPM, which then represents our minimal hardened trusted computing base on the telematics unit. The solution does not rely on boot time integrity mechanisms and thus even mitigates against advanced runtime and physical hardware cyberattacks. We evaluate our solution using a prototypical implementation within an automotive evaluation platform.
Christian Plappert, Andreas Fuchs 0002
ACSAC1
2023 Secure and Lightweight ECU Attestations for Resilient Over-the-Air Updates in Connected Vehicles
abstract
Recent automotive standards and regulations define requirements for over-the-air (OTA) software updates as a mandatory mitigation mechanism to secure the increasingly connected vehicles against future cyberthreats in a timely manner. Targeting these requirements, we design, implement, and evaluate a novel security concept targeted at securing the in-vehicle processes participating in the OTA update process. It is designed as complementary security measure to further harden already in-place secure update distribution mechanisms and is compliant to recent automotive standards and regulations. Its security is bootstrapped from the secure interlocking of two trusted computing technologies: The Trusted Platform Module 2.0 (TPM 2.0) as overall hardware trust anchor within the vehicle and the Device Identifier Composition Engine (DICE) for securely bootstrapping the resource constrained controllers. Our concept allows the controllers to report their currently running software version to the TPM 2.0 in a secure and lightweight way. Depending on the controllers’ software state, the TPM 2.0 may authorize to transition the vehicle from an update-ready state back to the fully functional drive mode, e.g., after an OTA software update was successfully installed.
Christian Plappert, Andreas Fuchs 0002
ACSAC1
2023 Evaluating the applicability of hardware trust anchors for automotive applications
abstract
The automotive trend towards autonomous driving and advanced connected services increases both complexity of the vehicle internal network and the connections to its environment. This introduced complexity further broadens the vehicle cyberattack surface. As mitigation strategy, state-of-the-art security mechanisms utilize so-called hardware trust anchors (HTAs) to protect security-sensitive data and processes in shielded locations that are isolated utilizing hardware security mechanisms. However, there is a variety of different HTAs with different functionality and security guarantees and there is currently no work done that compares and evaluates them against current and emerging automotive requirements. In this work, we evaluate the applicability of various HTAs to secure modern as well as upcoming future automotive applications. For this, we analyze and evaluate HTAs that are already established in the automotive field as well as promising HTAs from other domains. We extend our preliminary work [1] by increasing the range of the analyzed HTAs with solutions that are feasible for the most resource constrained automotive controllers and technologies that become feasible to be utilized by the introduction of high-performance controllers in future automotive architectures. We assess the different HTAs based on the evaluation criteria and in accordance to automotive requirements.
Christian Plappert, Dominik Lorych, Michael Eckel, Lukas Jäger, Andreas Fuchs 0002, Ronald Heddergott
Comput. Secur.1
2022 Analysis and Evaluation of Hardware Trust Anchors in the Automotive Domain
abstract
Automotive architectures get increasingly more complex both regarding internal as well as external connections to offer new services like autonomous driving. This development further broadens the cyberattack surface of modern vehicles. As mitigation mechanism, hardware trust anchors (HTAs) are increasingly integrated into the electronic control units (ECUs) of modern vehicles to shield security-sensitive data like cryptographic keys against a variety of cyberattacks. However, the provided security capabilities differ among the HTAs. There is currently no evaluation of the HTAs that also addresses current and emerging future requirements of the automotive domain. Thus, in this work, we will analyze and evaluate typical automotive HTAs regarding their feasibility to be used in modern and upcoming vehicle architectures. For this we derive comprehensive evaluation criteria from both related work as well as the automotive domain analysis and make an extensive assessment of the HTA properties in accordance to requirements of the automotive domain.
Christian Plappert, Andreas Fuchs 0002, Ronald Heddergott
ARES1
2022 SECPAT: Security Patterns for Resilient Automotive E / E Architectures
abstract
Automated driving requires increasing networking of vehicles, which in turn broadens their attack surface. In this paper, we describe several security design patterns that target critical steps in automotive attack chains and mitigate their con-sequences. These patterns enable the detection of anomalies in the firmware when booting, detect anomalies in the communication in the vehicle, prevent unauthorized control units from successfully transmitting messages, offer a way of transmitting security-related events within a vehicle network and reporting them to units external to the vehicle, and ensure that communication in the vehicle is secure. Using the example of a future high-level Electrical / Electronic (E / E) architecture, we also describe how these security design patterns can be used to become aware of the current attack situation and how to react to it.
Christian Plappert, Florian Fenzl, Roland Rieke, Ilaria Matteucci, Gianpiero Costantino, Marco De Vincenzi 0001
PDP1
2022 Towards a Privacy-Aware Electric Vehicle Architecture
abstract
Connected vehicles need to generate, store, process, and exchange a multitude of information with their environment. Much of this information is privacy-critical and thus regulated by privacy laws like the GDPR for Europe. In this paper, we analyze and rate exemplary data (flows) of the electric driving domain with regard to their criticality based on a reference architecture. We classify the corresponding ECUs based on their processed privacy-critical data and propose technical mitigation measures and technologies in form of generic privacy-enhancing building blocks according to the classification and requirements derived from the GDPR.
Christian Plappert, Jonathan Stancke, Lukas Jäger
PDP1
2021 Secure Role and Rights Management for Automotive Access and Feature Activation
abstract
The trend towards fully autonomous vehicles changes the concept of car ownership drastically. Purchasing a personal car becomes obsolete. Thus, business models related to feature activation are gaining even higher importance for car manufacturers in order to retain their customers. Various recent security incidents demonstrated however that vehicles are a valuable attack goal ranging from illegal access to car features to the theft of the whole vehicles.
Christian Plappert, Lukas Jäger, Andreas Fuchs 0002
AsiaCCS1
2021 Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
abstract
Connected smart cars enable new attacks that may have serious consequences. Thus, the development of new cars must follow a cybersecurity engineering process as defined for example in ISO/SAE 21434. A central part of such a process is the threat and risk assessment including an attack feasibility rating. In this paper, we present an attack surface assessment with focus on the attack feasibility rating compliant to ISO/SAE 21434. We introduce a reference architecture with assets constituting the attack surface, the attack feasibility rating for these assets, and the application of this rating on typical use cases. The attack feasibility rating assigns attacks and assets to an evaluation of the attacker dimensions such as the required knowledge and the feasibility of attacks derived from it. Our application of sample use cases shows how this rating can be used to assess the feasibility of an entire attack path. The attack feasibility rating can be used as a building block in a threat and risk assessment according to ISO/SAE 21434.
Christian Plappert, Daniel Zelle, Henry Gadacz, Roland Rieke, Dirk Scheuermann, Christoph Krauß
PDP1
2020 SEPAD - Security Evaluation Platform for Autonomous Driving
abstract
The development and evaluation of security solutions for autonomous vehicles is a challenging task. Many researchers have no access to real vehicles to implement and test their solutions. In addition, vehicle E/E architectures of different brands or even model series of one car manufacturer differ significantly. Also, vehicles may be the source of physical hazards, e.g., an exploding airbag. To enable researchers to develop, implement, and evaluate new security solutions for autonomous vehicles, we propose a new security evaluation platform called SEPAD and a dedicated development process for testing security mechanisms with it. SEPAD allows to model realistic E/E architectures where the developed security solutions can be integrated and evaluated without causing safety risks for the researcher or other road users.
Daniel Zelle, Roland Rieke, Christian Plappert, Christoph Krauß, Dmitry Levshun, Andrey Chechulin
PDP3
2018 The user-centered privacy-aware control system PRICON: An interdisciplinary evaluation
abstract
The advent of connected vehicles has increased the relevance of privacy in cars. While current approaches to increase security and privacy in connected vehicles are mainly driven from technological perspectives, users do not have active control over their personal data. Therefore, the user-centered privacy-aware control system PrivacyController (PRICON) has been developed which incorporates expertise from judicial, technical and user-centered perspectives. PRICON provides users with a user-friendly possibility to define self-determined privacy policies which are applied to the vehicular system. In this paper, we report the evaluation of PRICON from a legal, technical and user-centered point-of-view. The evaluation results are discussed and practical implications are derived.
Jonas Walter, Bettina Abendroth, Thilo Von Pape, Christian Plappert, Daniel Zelle, Christoph Krauß, G. Gagzow, Hendrik Decke
ARES4
2017 Secure Free-Floating Car Sharing for Offline Cars
abstract
In this paper, we present a new access control system for free-floating car sharing, which achieves a number of appealing features not available in the state-of-the-art solutions. First of all, it does not require online connection for cars, and, therefore, allows car sharing providers to expand their services to areas without reliable network coverage (e.g., with blind spots). Second, the solution is compatible to RFID cards -- the most commonly deployed authentication tokens in car sharing, and can be deployed on standard mobile platforms with various hardware features. Third, it is fully compatible with off-the-shelf cars and does not require any intrusive modifications to car's internals. These new properties can be achieved due to a novel system design which deploys two-factor authentication and combines an RFID card (the real one or emulated in software) with a "soft" authentication token stored on a mobile platform. Such a combination increases security of the solution, preserves backward compatibility to RFID technology and enables great flexibility in protection of authentication secrets on the mobile platform. To demonstrate such a flexibility, we present a platform security concept which can be instantiated in various deployment options and provides the means to achieve best possible security given available hardware.
Alexandra Dmitrienko, Christian Plappert
CODASPY2