scieee AI-readable full text Open interactive document viewer

Backward-compatible Software Upgrades for ADS-B and AIS To Support ECDSA-Secured Protocols

Saleem, Ahsan,Turtiainen, Hannu,Costin, Andrei,Hämäläinen, Timo

Full text

This is a self-archived version of an original article. This version may differ from the original in pagination and typographic details. Author(s): Title: Year: Version: Copyright: Rights: Rights url: Please cite the original version: CC BY-NC-ND 4.0 https://creativecommons.org/licenses/by-nc-nd/4.0/ Backward-compatible Software Upgrades for ADS-B and AIS To Support ECDSA-Secured Protocols © 2024 European Conference on Cyber Warfare and Security Published version Saleem, Ahsan; Turtiainen, Hannu; Costin, Andrei; Hämäläinen, Timo Saleem, A., Turtiainen, H., Costin, A., & Hämäläinen, T. (2024). Backward-compatible Software Upgrades for ADS-B and AIS To Support ECDSA-Secured Protocols. In M. Lehto, & M. Karjalainen (Eds.), Proceedings of the 23rd European Conference on Cyber Warfare and Security (23, pp. 446-456). Academic Conferences International Ltd. Proceedings of the European Conference on Cyber Warfare and Security. https://doi.org/10.34190/eccws.23.1.2250 2024 Backward-compatible Software Upgrades for ADS-B and AIS To Support ECDSA-Secured Protocols Ahsan Saleem, Hannu Turtiainen, Andrei Costin and Timo Hämäläinen Faculty of Information Technology, University of Jyväskylä, Jyväskylä, 40014 Finland ahsan.m.sa[email protected]i [email protected] [email protected] [email protected] Abstract: During the past few decades, the aviation, maritime, aerospace, and search-and-rescue domains have witnessed tremendous improvement thanks to technological, digitalization and Internet of Things (IoT) advances such as Automatic Dependent Surveillance–Broadcast (ADS-B) (e.g., Aviation IoT, Airports IoT) and Automatic Identification System (AIS) (e.g., Maritime IoT). All these are high-profile examples of new digital communication protocols combined with IoT devices that make efficient use of wide-area earth and space radio communications to provide real-time, truly globally interoperable, and optimised services required by these domains. However, the protocols and technologies mentioned above, both from an architectural and implementation point of view, exhibit fundamental cybersecurity weaknesses (both at protocol and IoT device level). These weaknesses make them an easy target for potential attackers. The two fundamental flaws of these protocols are the lack of digital signatures (i.e., integrity and authenticity) and the lack of encryption (i.e., confidentiality and privacy). The risks associated with these, and other weaknesses have been over the last decade repeatedly demonstrated with ease by ethical cybersecurity researchers. In this paper, we design, propose, and discuss a single generic PKI-enabled message integrity and authenticity scheme that works seamlessly for any of the ADS-B, and AIS, with the possibility of easy extension and integration into other protocols (e.g., ACARS). Our scheme can be added as backward-compatible software upgrades (e.g., third-party library) to existing systems without requiring expensive architectural redesign, upgrades, and retrofitting. Our present work is aimed to serve as a bootstrap to securing such insecure protocols without completely replacing or redesigning the systems. It also aims to provide a discussion background of advantages and limitations of such backward-compatible securing methods. Keywords: Cybersecurity, Protocol Upgrades, Message Authentication, ADS-B, 1090ES, AIS. 1. Introduction In aviation, aircrafts periodically broadcast their aviation data using a surveillance technique known as Automatic Dependent Surveillance-Broadcast (ADS-B). Air Traffic Control (ATC) and other airplanes receive this data, providing them with situational awareness. Currently, there are insufficient security measures to ensure the privacy, availability, and integrity of transmitting data between aircraft and air traffic controllers (Kožović et al., 2023) (Manesh and Kaabouch, 2017) (Strohmeier et al., 2013) (Wu et al., 2020). Consequently, an attacker may insert fake data or stop actual data from being correctly delivered because no authentication mechanisms are used at the data connection layer (Costin and Francillon, 2012) (Khandker et al., 2021) (Khandker et al., 2022a) (Mäurer et al., 2022). Various security schemes have been proposed to secure ADS-B transmission messages, including symmetric cryptographic-based (Chen, 2012) (Kacem et al., 2015), identity-based signature algorithms (Thumbur et al., 2019) (Yi et al., 2022), time-efficient stream loss-tolerant authentication (TESLA) protocol (Yang et al., 2018) (Sciancalepore and Di Pietro, 2019), anonymous authentication schemes (Asari et al., 2021) (Jegadeesan et al., 2021) and blockchain-based schemes (Wu et al., 2023) (Habibi Markani et al., 2023). In the maritime domain, vessel traffic services rely on the Automated Identification System (AIS) for automatic ship tracking. AIS is an open standard and due to unauthenticated and unencrypted nature make it vulnerable to threats such as spoofing, hijacking, and availability disruption (Balduzzi et al., 2014) (Hall et al., 2015) (Khandker et al., 2022b) (Tran et al., 2021). To secure AIS, several security schemes have been proposed, including anonymous authentication schemes (Goudosis and Katsikas, 2022) (Jegadeesan et al., 2021), TESLA protocol-based scheme (Sciancalepore et al., 2021) and blockchain based schemes (Duan et al., 2022) (Freire et al., 2022). In this study, we proposed authentication and integrity schemes for ADS-B (aviation) and AIS (maritime) systems. Despite the different domains, the architecture, technologies, and protocols of the ADS-B and AIS systems exhibit noteworthy similarities. Security threats and the proposed cybersecurity solutions are similar. Therefore, we propose a scheme that addresses the security concerns of both protocols to secure in our study. There are core motivations for our work. First and foremost, the bulk of the existing proposed solutions are either theoretical (Costin and Francillon, 2012) (Chen, 2012b) or require complete/major system redesign and 446 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al replacement in the case of practically demonstrated solutions (Thumbur et al., 2019) (Yang et al., 2014) (Goudossis and Katsikas, 2019) (e.g. introduction of new sub-protocols). Second, even for practically feasible solutions (Yang et al., 2018) (Sciancalepore et al., 2021) (Wimpenny et al., 2022), the proposed solutions are not uniform across multiple technologies and/or customised for each technology stack (that is, ADS-B-only, AISonly). This makes such solutions harder to maintain in the long run, brings more fragmentation to technology stacks, and increases the verification efforts of each individually customised approach. To address these limitations, we propose backward-compatible software only solution to provide stronger security to ADS-B and AIS protocols, which can easily be integrated with the existing systems and protocols. Our main contributions with this work are as follows: 1. We propose backward-compatible and software-only message authentication and integrity approach for existing insecure protocols in aviation (ADS-B). 2. We also propose a backward-compatible and software-only message authentication and integrity scheme for maritime (AIS). 3. We provide a security analysis of the proposed scheme, which shows that the proposed scheme is secured under a defined security model. 2. Related Work This section summarises the security and authentication-enhancing schemes previously proposed for ADS-B and AIS. Chen et al. (2012) proposed an ADS-B message confidentiality and authentication scheme based on block ciphers. Yang et al. (2015) proposed an ADS-B authentication batch verification scheme based on identity-based signature. Pan et al. (2012) proposed an elliptic curve cipher (ECC) and X.509 certificate-based authentication scheme for ADS-B. Thumbur et al. (2019) proposed an identity based authentication batch verification scheme for ADS-B. Yang et al. (2018) proposed confidentiality and integrity scheme for ADS-B transmission messages. Wu et al. (2019) proposed a certificate-less short signature-based authentication and integrity scheme for ADSB. Asari et al. (2021) presented hierarchical authentication and integrity scheme of ADS-B data based on a certificate-less public key cryptographic technique. Yang et al. (2014) proposed an identity signature based authentication and integrity scheme for ADS-B. Prakash et al. (2019) proposed an authentication scheme for ADS-B based on message authentication code (MAC). Recently blockchain-based security schemes for ADS-B are proposed in (Wu et al., 2023) (Habibi Markani et al., 2023). Sciancalepore et al. (2021) proposed an authentication scheme for AIS broadcast messages. Goudossis et al. (2019) proposed an authentication and integrity scheme for AIS, and in their follow-up work (Goudosis and Katsikas, 2020) addressed the implementation aspects of (Goudossis et al., 2019). Goudosis et al. (2022) proposed secure automatic identification system (SecAIS) that provides the authentication, confidentiality, and anonymisation of AIS messages. Wimpenny et al. (2022) proposed an elliptic curve based data integrity and authentication scheme for AIS. Su et al. (2017) proposed a digital certificate-based identity authentication scheme to ensure authentication and integrity of AIS data. Jegadeesan et al. (2021) proposed AIS anonymous authentication scheme. The blockchain-based authentication and integrity schemes for AIS are proposed in (Duan et al., 2022) (Freire et al., 2022). 2.1 Comparison with Existing Works Our present work is the best compared with the following existing works. In the ADS-B field, the work (Yang et al., 2018) is closest to our approach. However, this scheme is based on the TESLA protocol for authentication, which cannot be practically used in real-time authentication scenarios owing to the core idea of a delayed authentication mechanism due to symmetric key generation and distribution challenges. While our proposed approach is a public key cryptographic algorithm-based scheme which is real-time, backward-compatible, practical authentication scheme. In the AIS field, the schemes proposed by (Sciancalepore et al., 2021) (Wimpenny et al., 2022) are closest to our approach. These schemes are either inherently delayed authentication mechanisms or use separate VHF data-exchange system (VDES) side channels to carry digital signatures, which require the installation of new VDES hardware on the transmitter and receiver sides. However, our AIS proposed approach is real-time and practical and retains backward compatibility by carrying a signature payload in a “New type” of message in follow-up AIS communication. Moreover, our foremost differentiator, compared with the closest related work, is that our scheme provides a generic approach that adds cryptographically strong message authenticity and integrity to all protocols (e.g. ADS-B and AIS) in a single implementation. 447 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al 3. Preliminaries, Models and Goals This section provides background knowledge and defines our systems models of ADS-B and AIS, as well as the security goals of the proposed scheme. 3.1 ADS-B Model and Message Format The proposed ADS-B model is illustrated in Figure 1. ADS-B comprises two distinct communication subsystems: ADS-B OUT and ADS-B IN. In the proposed ADS-B model, an aircraft continuously transmits information regarding its altitude, velocity, and position through ADS-B OUT and ADS-B IN enables aircraft to receive nearby ADS-B messages transmitted by other aircraft or Air Traffic Control (ATC). The aircraft receives primary information from a navigation satellite, which is subsequently transmitted to another aircraft and the ATC through the ADSB OUT. The receiver aircraft receives this information using an ADS-B IN and then processes and displays it in the aircraft’s cockpit. Figure 1: General ADS-B Model (simplified) The ADS-B 112-bit message format, which consists of five fields, is illustrated in Figure 2. Figure 2: Long ADS-B 1090ES Message Format (112 bits) 3.2 AIS Model and Message Format The proposed AIS model is shown in Figure 3, where vessels and the AIS control center exchange navigation information, such as identification and position data, using a Global Navigation Satellite System (GNSS). This allows for various uses, such as identifying ships, tracking them from a distance, changing routes, and preventing and investigating accidents. 448 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al Figure 3: General AIS Model (simplified) In AIS, channel A communication uses a frequency of 161.975 MHz, whereas channel B uses 162.025 MHz. AIS message has an overall size of 256 bits (International Telecommunication Union, 2014),and its format is shown in Figure 4. Figure 4: AIS Message Format (256 bits) 3.3 Threat Model and Security Goals In adversary model, we assume that an adversary can intercept and modify the contents of the existing messages and may try to inject fake messages into the transmission channel following the ADS-B/AIS message format. In the absence of security measures, an adversary can intercept, retransmit, or delay transmitting messages, resulting in replay attacks. These attacker capabilities are realistic, as demonstrated by several studies (Costin and Francillon, 2012) (Khandker et al., 2021) (Khandker et al., 2022b) (Khandker et al., 2022a). These vulnerabilities enable eavesdropping, message injection, message modification, and replay attacks to occur. Moreover, the availability of low-cost software-defined radio (SDR) enables adversaries to launch these types of attacks. In our proposed schemes, we aim to achieve the following security goals. 1. Message Authentication: Message authentication means that incoming data on the receiver side are from an authentic source and the receiver can verify the message origin. Our proposed schemes ensure source authentication of the messages and ensure that the messages originate from the authenticated transmitter or source. 2. Message Integrity: Message integrity of the received message means that no one has tampered with the transmitting messages, and any modification should be detected at the receiver side. Our proposed schemes ensure the integrity of the transmitted messages and can detect and filter out tampered messages. 3. Resistance to False Data Injection Attack: An attacker may try to insert false data into a legitimate message. Any false data injected by an attacker should be easily detected on the receiver side when our scheme is employed. 4. Prevention of Replay Attack: Replay attack means that an adversary maliciously intercepts and delays or retransmits messages to the receiver. The receiver must be able to detect and filter replay messages. The proposed schemes can efficiently detect and discard replay messages. 5. Strong Cryptographic Guarantees: For stronger security, we use ECDSA 256-bit key signature algorithm over the SHA-256 hash of the message. This provides strong future-proof guarantees while simultaneously minimising the digital signature output at the same time. 449 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al An attacker model in which adversaries become mobile is called a mobile attacker or a mobile adversary model (Shang, 2023). We did not consider this type of attack in our threat model, which is an interesting extension of our work, and we consider for future exploration. Additionally, other types of attacks, such as denial of service and jamming attacks, are possible against ADS-B and AIS; however, these attacks are outside the scope of this study. 3.4 Non-Security Goals In addition to the security goals of our proposed scheme, we define the non-security goals of our schemes. 1. Backward Compatibility: This means that our schemes are software-only solutions and require no modification to existing protocols and hardware. 2. Single Generic Approach: The proposed schemes are software-only solutions, and we envision that our solution can work as a third-party library for upgraded systems. This will enable a single and generic code base that is easy to deploy and audit. 3. Minimum Communication Cost: For minimum communication cost, we consider a 512-bit length ECDSA signature algorithm in our scheme. 4. Proposed Solution In this section, we describe ADS-B and AIS authentication scheme. The notations used in the proposed scheme are listed in Table 1. Table 1: List of Notations Symbol Definition 𝐺𝐺 Generator 𝑘𝑘 Random number 𝑅𝑅 Random point 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 Private key 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 Public key 𝑇𝑇 𝑠𝑠 Timestamp ℎ Hash digest 𝜎𝜎 Signature 𝑑𝑑𝑑𝑑 𝑚𝑚 DF (ADS-B) message 𝑎𝑎𝑝𝑝𝑎𝑎 𝑚𝑚 AIS message 4.1 ADS-B Authentication This section provides source authentication and message integrity for the ADS-B messages. The proposed scheme consists of two algorithms: ADS-B Signature Generation and Encapsulation, and ADS-B Signature Verification and De-encapsulation. For authentication and message integrity, we use the ECDSA signature scheme. To maintain backward compatibility and openness of the ADS-B message, transmitter transmit a signed message of an ADS-B message (e.g. DF11 or DF17, which are the most common ADS-B messages in general) encapsulated within an ADS-B DF24 ELM message that follows-up. In this way, the transmitter continues to transmit ADS-B normally and transmits the respective signed message in a follow-up message using the DF24 ELM message. The message field of the ADS-B DF24 ELM is of 80-bits, and a full signature cannot be accommodated within a single packet. Therefore, to accommodate the digital signature data, we used a built-in message-chaining mechanism available in the ADS-B DF24 ELM, which can chain up to 16 segments related to the same ADS-B DF24 communication. The complete ADS-B authentication mechanism on the transmitter and receiver sides is illustrated in Figure 5. Given that the signature, timestamp, and ICAO take 600 bits, in practice, 8-chained DF24 ELM messages are required to transmit a digital signature of one standard ADS-B message. 450 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al Figure 5: Our proposed Message authenticity and integrity scheme 4.1.1 ADS-B Signature Generation and Encapsulation For ADS-B message signature generation and encapsulation of signed messages in the DF24 ELM message, transmitter used Algorithm 1. In the first step, it calculates timestamp 𝑇𝑇 𝑠𝑠. Then the transmitter computes the hash digest ℎ=ℎ𝑎𝑎𝑎𝑎ℎ(𝑑𝑑𝑑𝑑 𝑚𝑚∨ 𝑇𝑇 𝑠𝑠) of the full raw ADS-B 56bit or 112bit message (e.g., DF11 or DF17) concatenated with 𝑇𝑇 𝑠𝑠 using the hash algorithm 𝑆𝑆𝑆𝑆𝑆𝑆 −256. In next step, computes the signature 𝜎𝜎 of the hashed value ℎ using 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝. To prevent a replay attack, timestamp 𝑇𝑇 𝑠𝑠 is concatenated with a signed message. The message field of the DF24 ELM is of 80-bits. Therefore, the chaining mechanism of DF24 is used to encapsulate the signedmessage in the DF24 ELM and forward the “New type” of the ADS-B message to ATC. Algorithm 1: ADS-B Signature Generation and Encapsulation 1: procedure 2: Input: ADS-B message 𝑑𝑑𝑑𝑑 𝑚𝑚 , 𝑆𝑆𝑆𝑆𝑆𝑆 −256, 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 3: Output: Signature 𝜎𝜎= {𝑝𝑝,𝑎𝑎}, Encapsulated DF24 ELM 4: Compute timestamp 𝑇𝑇 𝑠𝑠 5: Calculate ℎ=ℎ𝑎𝑎𝑎𝑎ℎ(𝑑𝑑𝑑𝑑 𝑚𝑚 ∨ 𝑇𝑇 𝑠𝑠 ) using 𝑆𝑆𝑆𝑆𝑆𝑆 −256 6: Computes signature proof 𝜎𝜎=(𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝,ℎ) 7: Concatenate signature with ID and timestamp 𝜎𝜎 ∨ 𝑇𝑇 𝑠𝑠 ∨𝐼𝐼𝐼𝐼𝑆𝑆𝐼𝐼 8: Chaining signed message into 80-bits of the available payload of DF24 ELM 9: Transmit encapsulated DF24 ELM to ATC (or ADS-B IN aircraft/device) 10: end procedure 4.1.2 ADS-B Signature Verification and De-Encapsulation ATC receives the encapsulated DF24 ELM from the sender and authenticates the message using Algorithm 2. The first step de-encapsulates the DF24 ELM message and obtains 𝜎𝜎 ∨ 𝑇𝑇 𝑠𝑠 from the message field. ATC computes the hash digest as ℎ𝑎𝑎𝑎𝑎ℎ(𝑑𝑑𝑑𝑑 𝑚𝑚∨ 𝑇𝑇 𝑠𝑠) using the received timestamp and already received message (e.g., DF11, DF17, or any other ADS-B DF message for that purpose). Finally, the receiver verifies the signature using 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 of the sender and successful verification shows that the message originated from an authenticated source, and no one has tampered with the received message. The timestamp binding with the signature prevents replay attacks. 451 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al Algorithm 2: ADS-B Signature Verification and De-encapsulation 1: procedure 2: Input: Encapsulated DF24 ELM, ADS-B message 𝑑𝑑𝑑𝑑 𝑚𝑚 , 𝑆𝑆𝑆𝑆𝑆𝑆 −256, 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 3: Output: Authenticated data 4: De-encapsulate DF24 ELM message and get Signed message 𝜎𝜎 ∨ 𝑇𝑇 𝑠𝑠 ∨𝐼𝐼𝐼𝐼𝑆𝑆𝐼𝐼 5: Calculate ℎ=ℎ𝑎𝑎𝑎𝑎ℎ(𝑑𝑑𝑑𝑑 𝑚𝑚 ∨ 𝑇𝑇 𝑠𝑠 ) using 𝑆𝑆𝑆𝑆𝑆𝑆 −256 6: Signature validation using Public Key (𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝,ℎ,𝜎𝜎) 7: if Signature is validated then 8: Keep received message (Fully Authenticated) 9: else 10: Possibly tampered/replayed, therefore UNVERIFIABLE 11: end if 12: end procedure 4.2 AIS Authentication This section describes the proposed authentication and integrity scheme for AIS messages. The proposed AIS authentication scheme consists of two algorithms: AIS Signature Generation and Encapsulation, and the other is Signature Verification and De-encapsulation. AIS messages have overall size of 256-bit and containing 168-bit of the message field. In proposed scheme, we use an Elliptic Curve-based Digital Signature for source authentication and data integrity of the AIS message. The message field of an AIS message is 168 bits. Therefore, signed messages cannot be accommodated in this field. To overcome this problem, we use AIS Message Type 8 in our scheme for 4-consecutive slots. For the openness of the AIS protocol, we encapsulate signed messages into an existing protocol message, to which we apply a special interpretation. This process is illustrated in Figure 5. First, there is an AIS message, and then there is a follow-on message with a digital signature inside Message Type 8. This procedure retains the backward compatibility and openness of the AIS. This enables the transmitter to continuously transmit AIS messages normally and send signed messages to the receiver in follow-up messages. Given that the signature takes 512 bits with a timestamp of 64 bits, it requires 4-chained AIS Message Type 8 messages to transmit a digital signature of one standard AIS message. 4.2.1 AIS Signature Generation and Encapsulation In the proposed AIS authentication scheme, Algorithm 3 is AIS Signature Generation and Encapsulation, which signs the AIS message and encapsulates it into AIS Message Type 8. The transmitter first calculates timestamp 𝑇𝑇𝑠𝑠 and computes the hash digest ℎ𝑎𝑎𝑎𝑎ℎ(𝑎𝑎𝑝𝑝𝑎𝑎𝑚𝑚∨ 𝑇𝑇 𝑠𝑠) of the AIS message concatenated with timestamp 𝑇𝑇𝑠𝑠 using the hash algorithm 𝑆𝑆𝑆𝑆𝑆𝑆 −256. Then, the transmitter computes the signature proof 𝜎𝜎 using the 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝. To prevent a replay attack and to link the AIS message with the correct signed message on the receiver side, concatenate the timestamp 𝑇𝑇 𝑠𝑠 with the signature 𝜎𝜎 and finally encapsulate the signed message into AIS Message Type 8, and send this as a “New type” of AIS message to the AIS receiver(s). Algorithm 3: AIS Signature Generation and Encapsulation 1: procedure 2: Input: AIS message 𝑎𝑎𝑝𝑝𝑎𝑎 𝑚𝑚 , 𝑆𝑆𝑆𝑆𝑆𝑆 −256 3: Output: Signature 𝜎𝜎= {𝑝𝑝,𝑎𝑎}, Encapsulated AIS Message 4: Compute timestamp 𝑇𝑇 𝑠𝑠 5: Calculate ℎ=ℎ𝑎𝑎𝑎𝑎ℎ(𝑎𝑎𝑝𝑝𝑎𝑎 𝑚𝑚 ∨ 𝑇𝑇 𝑠𝑠 ) using 𝑆𝑆𝑆𝑆𝑆𝑆 −256 6: Computes signature proof 𝜎𝜎=(𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝,ℎ) 452 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024 Ahsan Saleem et al 7: Concatenate signature with ID and timestamp 𝜎𝜎 ∨ 𝑇𝑇 𝑠𝑠 8: Chaining signed message into 168-bits of the available payload of Message Type 8 9: Transmit encapsulated AIS messages to MTC or other Ship 10: end procedure 4.2.2 AIS Signature Verification and De-Encapsulation The AIS receiver receives the encapsulated AIS message from the transmitter, and Algorithm 4 de-encapsulates and authenticates the received AIS message. The first step de-encapsulates the AIS message and obtains the signed message concatenated with the timestamp 𝜎𝜎 ∨ 𝑇𝑇 𝑠𝑠. To link an already received AIS message with the received signed message and prevent a replay attack, it computes hash digest ℎ𝑎𝑎𝑎𝑎ℎ(𝑎𝑎𝑝𝑝𝑎𝑎𝑚𝑚∨ 𝑇𝑇 𝑠𝑠) using the received timestamp and with already received AIS message. The receiver then performs signature validation using 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 of the transmitter and signature verification ensures that the incoming data are from an authenticated source, and no one has tampered with the AIS message. Algorithm 4: AIS Signature Verification and De-encapsulation 1: procedure 2: Input: Encapsulated AIS Message, AIS message 𝑎𝑎𝑝𝑝𝑎𝑎 𝑚𝑚 , 𝑆𝑆𝑆𝑆𝑆𝑆 −256, 𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝 3: Output: Authenticated data 4: De-encapsulate AIS message and get Signed message 𝜎𝜎 ∨ 𝑇𝑇 𝑠𝑠 5: Calculate ℎ=ℎ𝑎𝑎𝑎𝑎ℎ(𝑎𝑎𝑝𝑝𝑎𝑎 𝑚𝑚 ∨ 𝑇𝑇 𝑠𝑠 ) using 𝑆𝑆𝑆𝑆𝑆𝑆 −256 6: Signature validation using Public Key (𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝𝑝,ℎ,𝜎𝜎) 7: if Signature is validated then 8: Keep received message (Fully Authenticated) 9: else 10: Possibly tampered/replayed, therefore UNVERIFIABLE 11: end if 12: end procedure Many of the proposed ADS-B and AIS message authentication and integrity schemes require modifications to existing protocols and transponders, resulting in a loss of compatibility for real-world deployment. However, our proposed ADS-B and AIS schemes are backward-compatible and retain the openness of protocols, thus requiring no hardware or protocol changes. 4.3 Assumptions, Constraints, Recommendations In this subsection, we enumerate the assumptions, constraints, and recommendations of the proposed schemes. 1. PKI and Key Management are out of Scope: In proposed schemes, we assume that PKI services are already established and readily available. Second, key management (i.e. generation, distribution, expiration, revocation, and reissue) is available with the upgraded system. 2. Cryptographic Computations: The systems upgraded with our solutions are supposed to have cryptographic computation capabilities (i.e., signature generation, signature verification) for both the transmitter and the receiver. Therefore, an upgraded system may have cryptographic modules to perform cryptographic computations. 3. Transmission Errors: We assume that our proposed schemes are not completely resistant to transmission errors introduced by the transmission medium or adversaries. We assume that the error detection and recovery capabilities of the underlying protocols are sufficient to avoid transmission errors; therefore, normal and signed messages are recoverable on the receiver side. 453 Proceedings of the 23rd European Conference on Cyber Warfare and Security, ECCWS 2024