4 ms·
I'm not sure whether you are confused or intentionally trying to be confusing but that doesn't make sense in the context of the discussed issue. The signing ke
by anon4242 3y ago
I'm not sure whether you are confused or intentionally trying to be confusing but that doesn't make sense in the context of the discussed issue.
The signing key would of course be unique per ECU/keyfob that needs to sign stuff so dumping another ECU doesn't help you crack it.
- TheLoafOfBread 3y agoThat private key needs to be stored somewhere otherwise your singing scheme does not work. Generating signing key is not really an option as you won't get enough entropy on the ECU and generated private keys will be oscillating around small group of prime numbers. Loading a new private key from the server? Well, thief's device can probably pretend to be a server and load a new private key into the control unit behaving as a master of immobilizer. Then the thief will get car and instantly new set of keys.
- labcomputer 3y ago> Generating signing key is not really an option as you won't get enough entropy on the ECU and generated private keys will be oscillating around small group of prime numbers. Erm... using the LSB of a network RX timer is common way to add entropy (and perfectly feasible here). You could also use the LSB of the +voltage rail sense or the thermometer that probably exists on your MCU.