This page was machine-translated and may differ from the original. View original
[Technical Contribution] ADI Michael Hate – How to Add Authentication Security to Vehicle Endpoints Using a Single PIN
Endpoint Safety Protection with a Single IC
DS28E40 adopts ECDSA public key security algorithm
Easily implement ECU host processor security layer
As the proportion of electronic devices used in vehicles increases, so do the vulnerable areas susceptible to hacker attacks.
Digital authentication can reduce the risk of theft and counterfeiting of high-quality genuine parts.
In critical automotive applications such as ADAS or electric vehicle (EV) batteries, counterfeit products can pose safety risks due to their inferior quality compared to genuine products.
Stolen parts may not function properly when used in other vehicles. In this case, adding a single authentication IC allows the component to be authenticated with only one signal between the ECU and the endpoint device (Figure 1).
▲Figure 1: ECU and Endpoint Block Diagram
The conventional approach to component security and authentication is to use secure microcontrollers or, furthermore, automotive Hardware Security Modules (HSMs).
Although it is a robust solution, this method is expensive, requires numerous electrical signals from the host controller, occupies a significant amount of PCB board space, and necessitates extensive software development and verification work to prevent bugs.
However, now, by simply adding a single compact fixed-function IC, the endpoint can be safely protected by transmitting only one signal along with a ground reference through a shielded cable between the ECU and the endpoint.
Analog Devices' DS28E40 implements a 1-wire protocol, which uses half-duplex communication and parasiticly generates power for device operation through the communication line, thereby reducing the need for a dedicated power line in the cable.
The energy generated in this way is stored in an external capacitor. Most automotive ECUs include high-performance microcontrollers and require only one open drain PIO pin along with a pull-up resistor for bidirectional communication.
Up to 16 mA is required for security algorithm computation, which exceeds the sourcing capacity of pull-up resistors.
If PIO1 can switch between an open drain and a push/pull configuration with sufficient current sourcing, it drives logic 1 during operation.
Alternatively, sufficient current can be supplied by adding a low-impedance bypass FET and controlling it using PIO2.
The DS28E40 adopts the ECDSA public key security algorithm and provides libraries and code examples, allowing for the easy implementation of a security layer on the ECU host processor.
Key management is simplified because this asymmetric security algorithm allows the host to read the unique public key directly from the DS28E40.
Next, when the host issues a random question message to the DS28E40, the DS28E40 responds to the question and digitally signs using its internal private key, which is never exposed to the outside world.
If the host verifies that this signature matches the public key, this endpoint gains trust from the ECU.
The DS28E40 has obtained AEC Q100 Grade 1 (-40C to +125C) certification and is available as a 3mm x 3mm side wettable frank (SWF) TDFN package.
※ Author Introduction
Michael Haight, Director of Business Management at Analog Devices, oversees embedded security products with a particular focus on automotive application business development. Michael, originally an IC design engineer, held various roles at Maxim Integrated (now acquired by ADI) for about 25 years, including product definition, application management, and what is now business management. Prior to joining the Maxim team at ADI, he held an IC design position at a defense contractor. Michael earned his BSEE from the University of Florida in 1993.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














