Generating audit records for distributed computing system-based motor vehicle
A process includes testing a motor vehicle using a distributed computing system. The distributed computing system includes a plurality of hardware components and a plurality of software components. The plurality of hardware components includes first hardware components of the vehicle and second hardware components that are separate from the vehicle. The plurality of software components includes first software components of the vehicle and second software components separate from the vehicle. The process includes, responsive to the testing, generating, by the distributed computing system, an audit record. Generating the audit record includes determining, by the distributed computing system, integrity measurements of the first hardware components, the second hardware components, the first software components and the second software components. Generating the audit record further includes comparing, by the distributed computing system, the integrity measurements to reference measurements that correspond to reference hardware configuration for the distributed computing system and a reference software configuration for the distributed computing system. Generating the audit record includes providing, by the distributed computing system, responsive to the comparison, digitally signed data for the audit record attesting to the distributed computing system having the reference hardware configuration and the reference software configuration in connection with the testing.
1 . A method comprising:
responsive to a test for a motor vehicle using a distributed computing system, verifying, by the distributed computing system, whether the test complies with a reference hardware configuration for the distributed computing system and the test complies with a reference software configuration for the distributed computing system, wherein the distributed computing system comprises an in-vehicle processing system of the motor vehicle and a second processing system external to the motor vehicle, wherein the distributed computing system comprises a plurality of hardware components and a plurality of software components, wherein the plurality of hardware components comprises first hardware components of the in-vehicle processing system and second hardware components of the second processing system, wherein the plurality of software components comprises first software components of the in-vehicle processing system and second software components of the second processing system, and wherein the verifying comprises:
determining, by the distributed computing system, integrity measurements of the first hardware components, the second hardware components, the first software components and the second software components, wherein the determining the integrity measurements comprises applying a cryptographic hash function to a value associated with at least one of the first hardware components, the second hardware components, the first software components and the second software components to derive a hash corresponding to a given integrity measurement of the integrity measurements; and
comparing, by the distributed computing system, the integrity measurements to reference measurements corresponding to the reference hardware configuration and the reference software configuration; and
managing the test responsive to a result of the verifying, wherein the managing comprises responsive to determining that the test complies with the reference hardware configuration and the reference software configuration, providing, by the distributed computing system, digitally signed data for audit records for the first hardware components, the second hardware components, the first software components and the second software components, and wherein the audit records attest to the distributed computing system having the reference hardware configuration and the reference software configuration in connection with the test, wherein providing the digitally signed data comprises encrypting a content corresponding to the integrity measurements with a cryptographic key to provide a digital signature corresponding to a given audit record of the audit records.
2 . The method of claim 1 , wherein the managing the test further comprises:
allowing the test responsive to the determining that the test complies with the reference hardware configuration and the reference software.
3 . The method of claim 1 , further comprising:
determining additional integrity measurements of data associated with the test,
wherein:
the comparing further comprises comparing the additional integrity measurements to a reference data configuration for the distributed computing system; and
the providing the digitally signed data further comprise providing digitally signed data for the given audit record attesting to the distributed computing system having the reference data configuration.
4 . The method of claim 1 , wherein the providing the digitally signed data comprises generating data representing a reference to a description of the reference hardware configuration and a reference to the reference software configuration.
5 . The method of claim 1 , wherein the test comprises performing at least one of an integration process, a verification process or a validation process.
6 . A system comprising:
a plurality of subsystems to collectively perform testing of a motor vehicle, wherein an in-vehicle subsystem of the plurality of subsystems corresponds to a component of the motor vehicle, wherein a second subsystem of the plurality of subsystems is external to the motor vehicle, wherein the in-vehicle subsystem comprises first hardware components and first software components, and wherein the second subsystem comprises second hardware components and second software components; and
a plurality of attestation engines comprising:
a first attestation engine associated with the in-vehicle subsystem to, responsive to the testing of the motor vehicle, verify whether the testing complies with a first reference hardware configuration for the in-vehicle subsystem and whether the testing complies with a first reference software configuration for the in-vehicle subsystem, wherein the verifying by the first attestation engine comprises determining integrity measurements of the first hardware components and the first software components, wherein the verifying comprises comparing the integrity measurements to the first reference hardware configuration and the first reference software configuration, wherein the first attestation engine to manage the testing, and wherein the managing of the testing by the first attestation engine comprises responsive to a determination by the first attestation engine that the testing complies with the first reference hardware configuration and the testing complies with the first reference software configuration, generating first audit data representing compliance of the testing with the first reference hardware configuration and the first reference software configuration, and applying a cryptographic hash function to the first audit data to generate a hash corresponding to a first signature for the first audit data; and
a second attestation engine associated with the second subsystem to, responsive to the testing of the motor vehicle, verify whether the testing complies with a second reference hardware configuration for the second subsystem and the testing complies with a second reference software configuration for the second subsystem, wherein the verifying comprises determining second integrity measurements of the second hardware components and the second software components, wherein verifying comprises comparing second integrity measurements to the second reference hardware configuration and the second reference software configuration, wherein the second attestation engine to manage the testing, and wherein the managing of the testing by the second attestation engine comprises responsive to a determination by the second attestation engine that the testing complies with the second reference hardware configuration and the testing complies with the second reference software configuration, generating second audit data representing compliance of the testing with the second reference hardware configuration and the second reference software configuration, and applying a cryptographic hash function to the second audit data to generate a hash corresponding to a second signature for the second audit data.
7 . The system of claim 6 , wherein:
the in-vehicle subsystem comprises a first component of the motor vehicle;
the first audit data represents an attestation to compliance of the first component with the first reference hardware configuration and the first reference software configuration;
the second subsystem comprises a computer system to simulate integration of the first component with a second component of the motor vehicle;
the second audit data represents an attestation to compliance of the computer system to the second reference hardware configuration and the second reference hardware configuration.
8 . The system of claim 7 , wherein the computer system comprises one of a computer platform having the same geographical location as the first component and a cloud computing system being located at a different geographical location than the first component.
9 . The system of claim 7 , wherein the first component comprises an electronic control unit (ECU).
10 . The system of claim 6 , wherein:
the testing comprises performing one of a driving test or a crash test of the motor vehicle;
the in-vehicle subsystem comprises a first component of the motor vehicle;
the first audit data represents an attestation to compliance of the first component with the first reference hardware configuration and the first reference software configuration;
the second subsystem comprises a computer system to acquire measurements from the motor vehicle responsive to the one of the driving test or the crash test;
the second audit data represents an attestation to compliance of the computer system to the second reference hardware configuration and the second reference hardware configuration.
11 . The system of claim 6 , wherein:
the testing comprises performing a test of the motor vehicle;
the in-vehicle subsystem comprises a first component of the motor vehicle;
the first audit data represents an attestation to compliance of the first component with the first reference hardware configuration and the first reference software configuration;
the second subsystem comprises a computer system to acquire measurements from the vehicle responsive to the test;
the second audit data represents an attestation to compliance of the computer system to the second reference hardware configuration and the second reference hardware configuration.
12 . The system of claim 6 , wherein:
the first audit data further represents compliance of a first data policy of the in-vehicle subsystem with a first reference data policy for the in-vehicle subsystem; and
the second audit data further represents compliance of a second data policy of the second subsystem with a second reference data policy for the second subsystem.
13 . The system of claim 12 , wherein the first reference data policy comprises at least one of:
a predefined input data set, a predefined output data set, a predefined set of configuration data; or a
predefined set of encrypted data.
14 . The system of claim 6 , wherein the first reference hardware configuration comprises at least one of a hardware device identification, a firmware identification or an operating system identification.
15 . The system of claim 6 , wherein the first reference software configuration comprises at least one of a software image measurement, software version number, a registry key, a register value or a port associated with a software service.
16 . The system of claim 6 , wherein:
the first audit data further contains data representing a reference to at least one record of a data repository containing a description of the first reference hardware configuration and the first reference software configuration; and
the second audit data further contains data representing a reference to at least one record of the data repository containing a description of the second reference hardware configuration and the second reference software configuration.
17 . The system of claim 6 , wherein the managing of the test by the first attestation engine further comprises responsive to the determination by the first attestation engine that the testing complies with the first reference hardware configuration and the testing complies with the first reference software configuration, allow the test.
18 . A non-transitory storage medium to store machine-readable instructions that, when executed by a distributed computing system, cause the distributed computing system to:
responsive to a test for a motor vehicle using the distributed computing system, verifying whether the test complies with a reference hardware configuration for the distributed computing system and the test complies with a reference software configuration for the distributed computing system, wherein the distributed computing system comprises an in-vehicle processing system of the motor vehicle and a second processing system external to the motor vehicle, wherein the distributed computing system comprises a plurality of hardware components and a plurality of software components, wherein the plurality of hardware components comprises first hardware components of the in-vehicle processing system-and second hardware components of the second processing system, wherein the plurality of software components comprises first software components of the in-vehicle processing system and second software components of the second processing system, and wherein the verifying comprises:
determining integrity measurements of the first hardware components, the second hardware components, the first software components and the second software components, wherein the determining the integrity measurements comprises applying a cryptographic hash function to a value associated with at least one of the first hardware components, the second hardware components, the first software components and the second software components to derive a hash corresponding to a given integrity measurement of the integrity measurements; and
comparing, by the distributed computing system, the integrity measurements to reference measurements corresponding to the reference hardware configuration and the reference software configuration; and
manage the test responsive to a result of the verifying, wherein the managing comprises responsive to determining that the test complies with the reference hardware configuration and the reference software configuration, providing, by the distributed computing system, digitally signed data for audit records for the first hardware components, the second hardware components, the first software components and the second software components, and wherein the audit records attest to the distributed computing system having the reference hardware configuration and the reference software configuration in connection with the test, wherein providing the digitally signed data comprises encrypting a content corresponding to the integrity measurements with a cryptographic key to provide a digital signature corresponding to a given audit record of the audit records.
19 . The storage medium of claim 18 , wherein the instructions, when executed by the distributed computing system, further cause the distributed computing system to generate audit data for the given audit record representing events occurring in the distributed computing system during the test.
20 . The storage medium of claim 18 , wherein the instructions, when executed by the distributed computing system, further cause the distributed computing system to, responsive to the test, generate digitally signed data for the given audit record representing a reference to a description of the reference hardware configuration and a reference to the reference software configuration.
21 . The storage medium of claim 18 , wherein the instructions, when executed by the machine, further cause the machine to responsive to determining that the test complies with the reference hardware configuration and the reference software configuration, allow the test.