Publications

Missing the Link? Enhancing the Security of Digital Car Keys with Secure Session Linking and Hardware Trust

AuthorPlappert, Christian; Trick, Daniel
Date2026
TypeConference Paper
AbstractThe deployment of digital car keys on personal devices, such as smartphones, offers new convenience features and business models. On the downside, this new connectivity increases the cyberattack surface of connected vehicles and enables scalable cyberattacks leading to unauthorized access to the vehicle. In this work, we design an enhanced security concept for digital car keys, which maintains the security properties of existing digital car key ecosystems even under an extended cyberthreat model where an attacker may exploit a protocol weakness that we call the "Missing Link Vulnerability". Our concept mitigates against this attack by cryptographically binding the device authentication and, optionally, sensor readings for distance bounding, to the vehicle access authorization step. All policy decisions are performed within the secure environment of a Trusted Platform Module (TPM) security chip to achieve additional protection against runtime and (hardware) side-channel attacks.
ConferenceAustralasian Conference on Information Security and Privacy 2026
ISSN03029743
Urlhttps://publica.fraunhofer.de/handle/publica/522194