ハードウェア認証とパケットタイミング透かしによるミッションクリティカルなロボット群の実践的ゼロトラスト
Practical Zero-Trust for Mission-Critical Robotic Fleets via Hardware Attestation and Packet Timing Watermarking
ROS 2ベースの無人車両群に対し、TPM 2.0によるハードウェア認証とパケット間遅延の統計的透かしを組み合わせたゼロトラストセキュリティフレームワークを提案・実証し、ステルス型中間者攻撃を完全検出した。
著者: Ryne Gonzales, Ethan Liesdyanto, Rex Worley, Michael Frederick, Jaewon Kim, Eman Hammad
分類: eess.SY, cs.MA
原文アブストラクト
Autonomous unmanned vehicles are vital to tactical missions, mission-critical public-safety operations like search and rescue and disaster response. However, their reliance on open wireless links and standard Robot Operating System (ROS 2) middleware exposes a broad cyber-physical attack surface. A compromise of these systems can disrupt real-time control loops, leading to mission failure or asset loss in high-stakes environments. This paper presents and empirically evaluates a layered, context-aware cybersecurity framework enforcing Zero-Trust principles for a multi-node robotic fleet over Wi-Fi. The framework integrates an active hardware root of trust (TPM 2.0), centralized in-band and out-of-band SIEM telemetry monitoring (ELK Stack and Kismet), and a non-cryptographic Inter-Packet Delay (IPD) timing watermark. Evaluated on a live ROS 2 mobile testbed under multi-layer exploits (OSI Layers 2-5), results demonstrate that while volume-based filters isolate brute denial-of-service floods, tracking the statistical sample kurtosis (K) of the embedded IPD watermark exposes stealthy Man-in-the-Middle command injections with complete detection accuracy without payload overheads.
関連論文
- LLM制御マルチロボット協調における単一ロボット侵害による不安全行動の伝播群制御/セキュリティ
- TriSweep: 電磁サイドチャネル解析のための4ドローンスウォームフレームワーク群制御/セキュリティ