Home / Series / Chaos Communication Congress / Aired Order / Season 36 / Episode 90

Vehicle immobilization revisited

(Uncovering and assessing a second authentication mechanism in modern vehicle immobilization systems) Modern road vehicles are fitted with an electronic immobilization system, which prevents the vehicle from starting unless an authorized transponder is present. It is common knowledge that the security transponder embedded in the key fob should be secure, and quite some work has been published on the (in)security of such transponders. However, we identify another crucial part of the immobilizer system, that has not yet received any academic attention. We investigated three vehicles, and found that the security transponder does not communicate with the ECM (Engine Control Module) but with the BCM (Body Control Module). After succesful authentication of the key, the BCM will then authenticate towards the ECM, after which immobilization is deactivated and the vehicle may start. If either the security transponder or this ECM-BCM authentication protocol is weak, vehicles may be started without presence of a valid security transponder.

English
  • Originally Aired December 28, 2019
  • Runtime 60 minutes
  • Production Code 11020
  • Created December 28, 2019 by
    Administrator admin
  • Modified December 28, 2019 by
    Administrator admin