<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="research-article" dtd-version="2.3" xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Comms. Net</journal-id>
<journal-title>Frontiers in Communications and Networks</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Comms. Net</abbrev-journal-title>
<issn pub-type="epub">2673-530X</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">1096841</article-id>
<article-id pub-id-type="doi">10.3389/frcmn.2023.1096841</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Communications and Networks</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Key parameters linking cyber-physical trust anchors with embedded internet of things systems</article-title>
<alt-title alt-title-type="left-running-head">Maasberg et al.</alt-title>
<alt-title alt-title-type="right-running-head">
<ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3389/frcmn.2023.1096841">10.3389/frcmn.2023.1096841</ext-link>
</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Maasberg</surname>
<given-names>Michele</given-names>
</name>
<xref ref-type="aff" rid="aff1">
<sup>1</sup>
</xref>
<xref ref-type="corresp" rid="c001">&#x2a;</xref>
<uri xlink:href="https://loop.frontiersin.org/people/2041654/overview"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Butler</surname>
<given-names>Leslie G.</given-names>
</name>
<xref ref-type="aff" rid="aff2">
<sup>2</sup>
</xref>
<xref ref-type="aff" rid="aff3">
<sup>3</sup>
</xref>
<uri xlink:href="https://loop.frontiersin.org/people/2092459/overview"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Taylor</surname>
<given-names>Ian</given-names>
</name>
<xref ref-type="aff" rid="aff4">
<sup>4</sup>
</xref>
</contrib>
</contrib-group>
<aff id="aff1">
<sup>1</sup>
<institution>Department of Cyber Science</institution>, <institution>United States Naval Academy</institution>, <addr-line>Annapolis</addr-line>, <addr-line>MD</addr-line>, <country>United States</country>
</aff>
<aff id="aff2">
<sup>2</sup>
<institution>Department of Chemistry</institution>, <institution>Louisiana State University</institution>, <addr-line>Baton Rouge</addr-line>, <addr-line>LA</addr-line>, <country>United States</country>
</aff>
<aff id="aff3">
<sup>3</sup>
<institution>Refined Imaging LLC</institution>, <addr-line>Baton Rouge</addr-line>, <addr-line>LA</addr-line>, <country>United States</country>
</aff>
<aff id="aff4">
<sup>4</sup>
<institution>SIMBA Chain</institution>, <addr-line>Plymouth</addr-line>, <addr-line>IN</addr-line>, <country>United States</country>
</aff>
<author-notes>
<fn fn-type="edited-by">
<p>
<bold>Edited by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1733761/overview">Adnan Anwar</ext-link>, Deakin University, Australia</p>
</fn>
<fn fn-type="edited-by">
<p>
<bold>Reviewed by:</bold> <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1732150/overview">Riadul Islam</ext-link>, University of Maryland, United States</p>
<p>
<ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/2520589/overview">Pramod Mathew Jacob</ext-link>, Providence College of Engineering and School of Business, India</p>
</fn>
<corresp id="c001">&#x2a;Correspondence: Michele Maasberg, <email>maasberg@usna.edu</email>
</corresp>
</author-notes>
<pub-date pub-type="epub">
<day>30</day>
<month>11</month>
<year>2023</year>
</pub-date>
<pub-date pub-type="collection">
<year>2023</year>
</pub-date>
<volume>4</volume>
<elocation-id>1096841</elocation-id>
<history>
<date date-type="received">
<day>12</day>
<month>11</month>
<year>2022</year>
</date>
<date date-type="accepted">
<day>14</day>
<month>11</month>
<year>2023</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#xa9; 2023 Maasberg, Butler and Taylor.</copyright-statement>
<copyright-year>2023</copyright-year>
<copyright-holder>Maasberg, Butler and Taylor</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p>
</license>
</permissions>
<abstract>
<p>Integration of the Internet of Things (IoT) in the automotive industry has brought benefits as well as security challenges. Significant benefits include enhanced passenger safety and more comprehensive vehicle performance diagnostics. However, current onboard and remote vehicle diagnostics do not include the ability to detect counterfeit parts. A method is needed to verify authentic parts along the automotive supply chain from manufacture through installation and to coordinate part authentication with a secure database. In this study, we develop an architecture for anti-counterfeiting in automotive supply chains. The core of the architecture consists of a cyber-physical trust anchor and authentication mechanisms connected to blockchain-based tracking processes with cloud storage. The key parameters for linking a cyber-physical trust anchor in embedded IoT include identifiers (i.e., serial numbers, special features, hashes), authentication algorithms, blockchain, and sensors. A use case was provided by a two-year long implementation of simple trust anchors and tracking for a coffee supply chain which suggests a low-cost part authentication strategy could be successfully applied to vehicles. The challenge is authenticating parts not normally connected to main vehicle communication networks. Therefore, we advance the coffee bean model with an acoustical sensor to differentiate between authentic and counterfeit tires onboard the vehicle. The workload of secure supply chain development can be shared with the development of the connected autonomous vehicle networks, as the fleet performance is degraded by vehicles with questionable replacement parts of uncertain reliability.</p>
</abstract>
<kwd-group>
<kwd>embedded sensors</kwd>
<kwd>internet of things</kwd>
<kwd>cyber-physical trust anchor</kwd>
<kwd>secure supply chain</kwd>
<kwd>blockchain</kwd>
</kwd-group>
<custom-meta-wrap>
<custom-meta>
<meta-name>section-at-acceptance</meta-name>
<meta-value>Security, Privacy and Authentication</meta-value>
</custom-meta>
</custom-meta-wrap>
</article-meta>
</front>
<body>
<sec sec-type="intro" id="s1">
<title>1 Introduction</title>
<p>Consider the question &#x201c;Why will a modern automobile, with over 100 million lines of code,<xref ref-type="fn" rid="fn1">
<sup>1</sup>
</xref> tolerate the installation of counterfeit parts?&#x201d; The modern automobile has exceptional computational power and facile Internet access to secure databases (<xref ref-type="bibr" rid="B41">Zhang et al., 2022</xref>) which, when combined with embedded sensors and Internet of Things (IoT) concepts, have the potential to facilitate part authentication along the automotive supply chain from manufacture through installation and acceptance by connected and autonomous vehicle driving networks. Herein, we ask what can be done in the repair process to ensure authentic parts are installed during automotive repairs?</p>
<p>In this work, we review the magnitude of the counterfeit automobile parts problem and attempted solutions. The automobile counterfeit problem ranks fourth among commodity items in commerce today, with deadly results for the vehicle occupants. Today, parts are usually validated based on identifying marks on packaging, which is inadequate, hence the motivation for embedded sensors as described in this Journal.</p>
<p>We note the rapid growth of research in the cyber security of vehicles, infrastructure, and autonomous vehicles. We suggest that forthcoming autonomous vehicle policies should include required processes for counterfeit detection of repair parts installed in the autonomous vehicles else the system-wide failure rate due to counterfeit items on members of the autonomous fleet will become unacceptable.</p>
<p>Our contributions are summarized as follows.<list list-type="simple">
<list-item>
<p>&#x2022; We develop an architecture for anti-counterfeiting in automotive supply chains with key components linking a trust anchor with systems, data, sensors, and monitoring.</p>
</list-item>
<list-item>
<p>&#x2022; We advance trust anchor technology and develop a new model based on acoustic signatures for installed automotive components linked to embedded sensors systems.</p>
</list-item>
<list-item>
<p>&#x2022; We integrate cost effective security features into the process.</p>
</list-item>
</list>The rest of the paper is organized as follows. <xref ref-type="sec" rid="s2">Section 2</xref> presents a background and review of current anti-counterfeiting technologies for automotive embedded systems, highlighting the gaps for a secure supply chain. In <xref ref-type="sec" rid="s3">section 3</xref>, the architecture is developed based on key components linking the technology and systems, integrating a current model. In <xref ref-type="sec" rid="s4">Section 4</xref>, the model is advanced for automotive embedded systems, incorporating acoustic signature for authentication along with discussion and analysis of this work. In <xref ref-type="sec" rid="s5">Section 5</xref>, conclusions and future work are discussed.</p>
</sec>
<sec id="s2">
<title>2 Background</title>
<sec id="s2-1">
<title>2.1 Magnitude of the problem</title>
<p>Counterfeit automotive parts pose serious risks to public safety. They are among the most dangerous counterfeits due to risk of harm, injury, or death.<xref ref-type="fn" rid="fn2">
<sup>2</sup>
</xref> According to the World Health Organization, approximately 1.3 million deaths and 20&#x2013;50 million injuries annually are caused by motor vehicle accidents; in India, approximately 20% of the accidents are attributed to counterfeit automotive parts (<xref ref-type="bibr" rid="B35">Shen et al., 2022</xref>).</p>
<p>Automotive parts and electronics are currently among the top four most commonly counterfeited products.<xref ref-type="fn" rid="fn3">
<sup>3</sup>
</xref> Demand for counterfeit automotive parts has nearly tripled in the wake of the global COVID-19 pandemic due to increased costs and shortage of replacement parts. The integration of automotive embedded devices in IoT further increased demand for fake parts due to a shortage in electronic components.</p>
<p>The magnitude of automotive counterfeiting is staggering. Toyota Australia recently reported that 62% of their products online were counterfeit.<xref ref-type="fn" rid="fn4">
<sup>4</sup>
</xref> BMW has reported fakes from Amazon, eBay, and other online marketplaces. German automaker Daimler AG discovered $1.7 million in counterfeit parts in 1&#xa0;year. In July 2021, U.S. Customs and Border Protection seized 5,657 counterfeit ($295,302) vehicle parts from China. In 2022, automotive parts suppliers in three retail stores were charged with selling counterfeits in New York.</p>
<p>Counterfeiters tend to focus on profitable automotive parts that are most often replaced. Commonly counterfeited auto parts include brake pads, lights, tires, rims, windscreens, and body parts. These parts are counterfeited in high volumes, and they can lead to premature failure, injuries, and accidents. <xref ref-type="fig" rid="F1">Figure 1</xref>
<xref ref-type="fn" rid="fn5">
<sup>5</sup>
</xref> depicts commonly counterfeited parts that are particularly dangerous, including airbags, engine components, and brakes.</p>
<fig id="F1" position="float">
<label>FIGURE 1</label>
<caption>
<p>Commonly counterfeited high risk automotive components. Source: reproduced with permission from Automotive Anti-Counterfeiting Council (A2C2), 2023<xref ref-type="fn" rid="fn5">
<sup>5</sup>
</xref>.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g001.tif"/>
</fig>
<p>The detection of counterfeit automobile parts should be coordinated with the growing field of cyber security of autonomous vehicles. The research activity in this field is, recently, very high. For example (<xref ref-type="bibr" rid="B21">Kennedy et al., 2019</xref>), discuss automotive cyber security from the viewpoint of criminology theory and vehicle-related cybercrime. Especially pertinent to this work is the role of guardianship strategies. Collaboration and information sharing among automakers, suppliers, policymakers, and security researchers is an effective approach counterfeit and other cybercrime prevention.</p>
<p>There is an opportunity to merge counterfeit prevention with the cyber technologies and policies under development protecting vehicles. Ensuring security of authentication systems poses a significant challenge. Advanced anti-counterfeiting architectures are based on embedded systems, IoT, sensing, networking, and communication technologies. Currently, these technologies in vehicles are vulnerable. A remote attack was demonstrated in 2015 by security researchers with the compromise of a 2014 Jeep Cherokee&#x2019;s electronic functions.<xref ref-type="fn" rid="fn6">
<sup>6</sup>
</xref> The researchers were able to control everything from locks to steering by attacking the Jeep&#x2019;s Controller Area Network (CAN) bus system through the entertainment system. Further research into connected vehicle vulnerabilities revealed that the on-vehicle computer and communication systems are unsecured. (<xref ref-type="bibr" rid="B20">Hashem Eiza and Ni, 2017</xref>; <xref ref-type="bibr" rid="B13">El-Rewini et al., 2020</xref>; <xref ref-type="bibr" rid="B23">Khan et al., 2020</xref>; <xref ref-type="bibr" rid="B2">Aliwa et al., 2021</xref>; <xref ref-type="bibr" rid="B12">Elkhail et al., 2021</xref>; <xref ref-type="bibr" rid="B22">Khan et al., 2022</xref>; <xref ref-type="bibr" rid="B26">Labrado et al., 2022</xref>). Other connected vehicles communications could be compromised, including transmission of geolocation data (<xref ref-type="bibr" rid="B25">Kumar et al., 2019</xref>), communication with charging stations for electric vehicles (<xref ref-type="bibr" rid="B1">Acharya et al., 2020</xref>), and communication with traffic signals (<xref ref-type="bibr" rid="B14">Feng et al., 2022</xref>). If vehicle systems are not secured, then counterfeit detection and monitoring systems could also be easily compromised.</p>
<p>In the next section, we review current anti-counterfeiting strategies and highlight the gaps in anti-counterfeiting technology for automotive supply chains.</p>
</sec>
<sec id="s2-2">
<title>2.2 Current anti-counterfeiting strategies</title>
<p>The automotive industry relies heavily on customer education to fight counterfeits. One of the leading recommendations for customers to spot fakes is inspection of the packaging. The automobile parts supply chain relies heavily on packaging to establish part authenticity. <xref ref-type="fig" rid="F2">Figure 2</xref> shows an example of authentic and counterfeit packaging, where color and print errors reveal the counterfeit part.<xref ref-type="fn" rid="fn7">
<sup>7</sup>
</xref> A true counterfeit, as opposed to a generic replacement, copies the appearance, dimensions, color, and logos of an authentic part down to the packaging. Counterfeiters often fail at reproducing packaging that is hard to duplicate. However, they are continuously enhancing their techniques to replicate intricate packaging on a larger scale.</p>
<fig id="F2" position="float">
<label>FIGURE 2</label>
<caption>
<p>ACDelco&#x2019;s authentic packaging (left) has been copied, as shown on the right, for a fake spark plug.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g002.tif"/>
</fig>
<p>Another leading strategy to avoid automotive counterfeit components is to encourage customers to purchase from a legitimate source. A recent arrest of automotive parts suppliers in the U.S. for selling counterfeit auto replacement parts demonstrates that packaging and validity of supplier are ineffective with the increasing sophistication of counterfeiters.</p>
<p>Automakers, Original Equipment Manufacturers (OEM), and suppliers play integral roles within the automotive supply chain, wherein each entity bears a significant responsibility to prevent counterfeits. Recently, these companies have stepped up their efforts to combat counterfeit parts. For example, many have issued counterfeit warnings, initiated lawsuits against counterfeiters, embarked on counterfeit education campaigns, and become members of anti-counterfeiting organizations like Automotive Anti-Counterfeiting Council (A2C2)<xref ref-type="fn" rid="fn6">
<sup>6</sup>
</xref>. For example, BMW and Honda both issued counterfeit product alerts and guidance on how to spot fakes. BMW also tracks the sources of fakes from customers, which include Amazon, eBay, other online vendors, and retail stores.</p>
<p>A Google search of &#x201c;Gates timing counterfeit&#x201d; yields websites sponsored by Gates Corporation in their effort to ensure a secure supply chain. Unfortunately, counterfeit timing belts have entered the automobile parts supply chain. One feature available through the website is authentication via a serial number. Unfortunately, the serial number is printed on the opaque package, so the contents are not easily verified.</p>
<p>The current anti-counterfeiting strategies in the automotive supply chain are insufficient. Multi-pronged anti-counterfeiting efforts and methods are needed as counterfeiting becomes more sophisticated. Physical, cyber-physical, and technical anti-counterfeiting techniques and processes must be implemented in conjunction with legal measures to secure the automotive supply chain.</p>
</sec>
<sec id="s2-3">
<title>2.3 Supply chain and the need for anti-counterfeiting technology</title>
<p>The supply chain is vulnerable in the absence of anti-counterfeiting technology. A recent lawsuit revealed a problem with Kona coffee, coffee grown in Hawaii (Bruce Corker et al. v. Costco Wholesale Corp. et al., 2:19-CV-00290-RSL (Western District of Washington at Seattle, 25 June 2021). The annual Kona coffee bean production in Hawaii was 2.7 million pounds, yet annual retail sales exceeded 20 million pounds. Farmers in the Kona region of Hawaii sued more than 20 retailers for selling counterfeit coffee after lab testing revealed that beans being sold were not from Kona. While the lawsuit reimburses the farmers, it is not at all clear if the underlying problem is solved.</p>
<p>The Kona coffee lawsuit illustrates the cost to legitimate companies incur from counterfeiting. In the automotive supply chain, manufacturers lose approximately $2 billion annually to counterfeit tires and batteries. Virtually any automotive part can be counterfeited, as shown in <xref ref-type="fig" rid="F1">Figure 1</xref>. The automotive supply chain also includes the aftermarket and spare parts, where the prevalence of counterfeit parts is increasing. <xref ref-type="fig" rid="F3">Figure 3</xref> shows mission critical parts, one of which is counterfeit.<xref ref-type="fn" rid="fn8">
<sup>8</sup>
</xref> Chemical analysis would show the authentic part to have a metal-ceramic pad whilst counterfeit brake pads has been found with cellulose/resin composites and to have extremely poor braking performance. We note the absence of any authentication mechanism on the part.</p>
<fig id="F3" position="float">
<label>FIGURE 3</label>
<caption>
<p>The automobile part, isolated from the vehicle&#x2019;s communication network, are difficult to authenticate. The (left) authentic brake pad is difficult to distinguish from (right) the counterfeit brake pad, once installed on the vehicle.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g003.tif"/>
</fig>
<p>Current supply chain risk management standards require tests and inspections to determine component authenticity.<xref ref-type="fn" rid="fn9">
<sup>9</sup>
</xref> Inspection to verify part identity requires technologies to facilitate authentication. The United States National Institute of Standards and Technology (NIST) refers to technologies that verify identity of authentic hardware and software in digital environments as a &#x201c;trust anchor.&#x201d; The NIST mission statement is &#x201c;To promote U.S. innovation and industrial competitiveness by advancing measurement science, standards, and technology in ways that enhance economic security and improve our quality of life.&#x201d; In April 2022, the NIST center, the National Cybersecurity Center of Excellence (NCCoE) published the report NIST.IR 8419 &#x201c;Blockchain and Related Technologies&#x2026;&#x201d;.<xref ref-type="fn" rid="fn10">
<sup>10</sup>
</xref> The industry case studies listed in the report span a range of points of view, ranging from food, aerospace and traditional manufacturing to digital signatures and embedded trust anchors, collectively called cyber-physical trust anchors. The authors participated in the NIST NCCoE working group discussions and believe the report represents a valid snapshot of many manufacturing supply chains today. Other topics of concern included identity, traceability, linking physical objects to data and records, interoperability, metrics, and standards. In the following sections, we discuss the cyber-physical trust anchor implementation in our work, identify the key parameters linking it to automotive systems developing our model, and describe security features.</p>
</sec>
</sec>
<sec id="s3">
<title>3 Proposed architecture with cyber-physical trust anchors</title>
<p>In this section, we develop an architecture for anti-counterfeiting in automotive supply chains with crucial components linking a trust anchor with systems, data, sensors, and monitoring. The core of the architecture consists of a cyber-physical trust anchor and authentication mechanisms connected to tracking processes. The key parameters for linking a cyber-physical trust anchor in embedded IoT include identifiers (i.e., serial numbers, special features, hashes), authentication algorithms, blockchain, and sensors. We use the US $100 currency as an example of the origin of the hashes as a unique identifier, and then an example of quite simple hashes, coupled with blockchain, bringing security to a coffee bean supply chain. Following the use case with tracking coffee, we advance the architecture to include acoustic signature for tires.</p>
<sec id="s3-1">
<title>3.1 Trust anchors</title>
<p>Many organizations address counterfeiting with legal measures and physical anti-counterfeiting techniques. For example, in the United States, the Secret Service investigates financial crimes, and currency includes a number of features to authenticate it with inspection. The US $100 currency, shown in <xref ref-type="fig" rid="F4">Figure 4</xref>, has at least twelve physical trust anchors&#x2014;paper, printing, ink, ribbon&#x2014;and each bill has a unique serial number<xref ref-type="fn" rid="fn11">
<sup>11</sup>
</xref>. It is believed the serial number is tracked throughout the banking system. Hence, low-quality counterfeit bills are detected by flaws in the physical trust anchors and high-quality counterfeits, the &#x201c;superbills&#x201d;, are detected by mismatch of the serial number.</p>
<fig id="F4" position="float">
<label>FIGURE 4</label>
<caption>
<p>A US $100 dollar bill to illustrate trust anchors in a physical object of high value. The serial number is used to generate a cryptographic hash and the perceptual hash is generated from the features, some of which are labeled above.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g004.tif"/>
</fig>
<p>The $100 currency anti-counterfeiting techniques can be transferred to the digital world. The serial number and composite of features in currency can be transformed into unique digital identifiers, constituting a digital trust anchor. An effective mechanism for linking unique digital identifiers to cyber records is hashing. A cryptographic hash is limited to perceptibly different items, and a perceptual hash uses features that are similar under small change. The similarity between perceptual hashes is quantified by computing distance between the hashes.</p>
<p>We use hashes for generating different two types of fingerprints for authenticity. A cryptographic hash enables bit-by-bit authenticity using content based verification. However, a cryptographic hash bares no correlation in the hash space to the input space; this makes them exceedingly powerful at detecting identical images but not similar ones. A perceptual hash, on the other hand, proves verification of the image by generating a comparable fingerprint representation of the image. One perceptual hash of an image will be closer in distance to a similar image that a non similar image. Perceptual hashes are also insensitive to different codecs and updates to the media metadata.</p>
<p>Cyber-physical trust anchors can use a variety numerical structures for linking physical attributes of an object with a secure database. For the purpose of this discussion, we label the serial number as a &#x201c;cryptographic hash&#x201d; and the ink, print details, etc., as a &#x201c;perceptual hashes&#x201d;. Then, each hash has its own definition of distance. The distance for a cryptographic hash is either zero or one, i.e., a perfect match or not. The Euclidean distance in a perceptual hash is a positive real number, i.e., a small positive number for a near perfect match or larger for poor match.</p>
<p>In a truth table of possibilities, an amateur&#x2019;s counterfeit $100 currency is detectable based on large perceptual hash distance, i.e., many print errors and flaws, and a cryptographic hash distance of zero, the counterfeited serial number is not contained in the database at the US. Federal Reserve. A superbill will have a small perceptual hash distance&#x2014;it looks authentic&#x2014;yet the cryptographic hash distance is zero, the counterfeited serial number is not contained in the database at the US. Federal Reserve, so long as the database is not compromised.</p>
</sec>
<sec id="s3-2">
<title>3.2 Security considerations</title>
<p>A cyber-physical trust anchor is a component of the broader identification, authentication, authorization, and accounting framework for access controls. The lack of end-to-end access control solutions has been an ongoing concern in conventional automotive supply chain security. Although IoT transformed the supply chain with efficiency in tracking, prediction, and automation, challenges exist in connectivity, sensor selection and costs, battery life, and security.</p>
<p>The potential for cyber attacks on vehicles, infrastructure, and autonomous networks has already yielded some protective actions: situation reviews (<xref ref-type="bibr" rid="B8">Chen et al., 2022</xref>; <xref ref-type="bibr" rid="B34">Sharma and Gillanders, 2022</xref>), policy recommendations (<xref ref-type="bibr" rid="B17">Girdhar et al., 2022</xref>; <xref ref-type="bibr" rid="B22">Khan et al., 2022</xref>; <xref ref-type="bibr" rid="B24">Kukkala et al., 2022</xref>; <xref ref-type="bibr" rid="B5">Benyahya et al., 2023</xref>), honey-pots (<xref ref-type="bibr" rid="B31">Panda et al., 2022</xref>; <xref ref-type="bibr" rid="B3">Anastasiadis et al., 2023</xref>; <xref ref-type="bibr" rid="B4">Baldo et al., 2023</xref>), and attack detection (<xref ref-type="bibr" rid="B7">Chen et al., 2021</xref>; <xref ref-type="bibr" rid="B40">Zelle et al., 2022</xref>; <xref ref-type="bibr" rid="B42">Zhang et al., 2023</xref>). This activity demonstrates a high level of concern for the cybersecurity of vehicles, infrastructure, and autonomous vehicles.</p>
<p>We note the interest of the economic sector in the discussions on cyber security in the automotive industry. Authors at the Lloyds Banking Group (London UK) have recently published a literature review, noting gaps in the technology and proposed standards (<xref ref-type="bibr" rid="B15">Fernandez de Arroyabe et al., 2022</xref>). The technology and standards gaps are visually presented in a system dynamics model (<xref ref-type="bibr" rid="B22">Khan et al., 2022</xref>). In a 2021 review article on future research directions for secure supply, blockchain is described as a promising candidate (<xref ref-type="bibr" rid="B9">Cheung et al., 2021</xref>). A 2022 article on zero trust architecture (<xref ref-type="bibr" rid="B33">Rose et al., 2020</xref>) gives a more detailed analysis of the role of blockchain for access control (<xref ref-type="bibr" rid="B37">Syed et al., 2022</xref>). One issue is privacy, and a strategy is proposed for employing blockchain for security objectives while maintaining private product information and business relationships (<xref ref-type="bibr" rid="B41">Zhang et al., 2022</xref>).</p>
</sec>
<sec id="s3-3">
<title>3.3 Authentication and tracking</title>
<p>Part traceability in automotive supply chains is predicated on certainty that the part is genuine from factory to customer. In this work, parts are authenticated at point of reading the cyber-physical trust anchor, and establishing provenance. When a part is created, the cyber-physical trust anchor is registered in a secure database with auditing capabilities. The audit logs must be resistant to attackers hiding their actions.</p>
<p>Blockchain is an ideal technology for auditing and tracking due to immutable logs. Each block contains the cryptographic hash of the previous block, timestamp, and transaction data. Since a cryptographic hash function is used for linking two nodes (i.e., each event is appended to the cryptographic hash of the preceding event), the integrity of events is ensured.</p>
<p>The authentication process can be automated with capture and encoding of data and signals, and readout with sensors. For example, GS1 global standards for streamlining traceability include Two-Dimensional (2D) barcodes, Quick Response (QR) codes, and radio-frequency identification (RFID) (<xref ref-type="bibr" rid="B19">GS1, 2021</xref>). Past research has examined RFID for authentication and tracking of patients in healthcare settings (<xref ref-type="bibr" rid="B38">Wamba and Chatfield, 2009</xref>; <xref ref-type="bibr" rid="B30">Mabad et al., 2021</xref>). Within this Journal, there are a few very popular embedded sensors, with RFID tags being one of the leading examples (<xref ref-type="bibr" rid="B11">Elgazzar et al., 2022</xref>; <xref ref-type="bibr" rid="B28">Lin et al., 2022</xref>; <xref ref-type="bibr" rid="B29">Lv, 2022</xref>). For a proof-of-concept, we use an non-RFID solution&#x2014;QR codes, mass, and moisture content&#x2014;in a use case with tracking Toks coffee, <xref ref-type="sec" rid="s3-4">Sec. 3.4</xref>. Then, we explore non-RFID solutions such as acoustic signatures, as described in <xref ref-type="sec" rid="s4-2">Sec. 4.2</xref>, for vehicle applications.</p>
<p>In the next section, we briefly discuss results from a nearly 2-year long application of blockchain to provide a secure supply chain.</p>
</sec>
<sec id="s3-4">
<title>3.4 Use case: Secure coffee beans with blockchain and simple trust anchors</title>
<p>In January 2021, small farmers in the Tacan&#xe1; Natural Reserve<xref ref-type="fn" rid="fn12">
<sup>12</sup>
</xref>&#x2014;a distinct biosphere around the Tacan&#xe1; Volcano in Chiapas, Mexico, on the border with Guatemala&#x2014;started using a secure supply chain developed by Dr. Ian Taylor, chief technical officer of SIMBA Chain and his colleagues. The problem solved was an inefficient, and sometimes unfair, supply chain. With blockchain and a very simple physical trust anchor&#x2014;mass and moisture content&#x2014;the outcome has been a secure supply chain from individual farmers to more than 200 Toks Restaurants across Mexico. <xref ref-type="fig" rid="F5">Figure 5</xref> shows the different tiers in the supply chain. A bag of coffee (about 100&#xa0;kg) is delivered from a farm to the cooperative. The cooperative uses an app on a tablet to register the bag of coffee, measuring the weight and humidity amongst other attributes, and then the farmer digitally signs to hand off in return for payment. A QR code for the bag is generated and registered on the blockchain. The bag of coffee then is sent to the desheller (also registered on chain) and when it returns, the new weight and humidity are measured. The new weight will be roughly 70&#xa0;kg but each bag is different. Also, the bean&#x2019;s moisture content for each bag will vary. These new measurements are recorded on chain and associated with the QR code. This coupling of the physical attributes with a QR code makes counterfeiting extremely challenging. A counterfeiter cannot simply copy the QR code onto a fake bag of deshelled coffee because it would be very unlikely that the weight and moisture content would match. This simple scheme therefore provides sufficient authenticity and, based on a 4-fold increase in income to the farmer, is a robust anti-counterfeit mechanism.</p>
<fig id="F5" position="float">
<label>FIGURE 5</label>
<caption>
<p>Coffee bean bags with QR labels, mass, and moisture content, when linked to blockchain by a cell app, is sufficient to track sustainably-grown coffee beans from farmer to restaurant. The evidence for success is a 4-fold increase in farmer income.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g005.tif"/>
</fig>
<p>For the restaurant customers, the secure supply chain ensures the coffee is sustainably sourced. The supply chain has become more efficient, and the return to the farmer increased from $50/bag to $200/bag.<xref ref-type="fn" rid="fn13">
<sup>13</sup>
</xref>
</p>
<p>The on-going cost is paper labeling, measurement of weight and moisture content of the coffee beans, a cell phone app, and a blockchain-secured database. These costs are minimal, and barely more than normal product tracking, yet the combination of simple trust anchors linked to a blockchain has a massive, favorable impact on the supply chain. Blockchain in batches distributed across many areas is cheaper than using RFID. Just the cost of a single passive RFID tag can be 50 cents per tag. Blockchain is particularly cost effective when implemented in a private blockchain, as it is in this model. Is the model of a simple trust anchor with blockchain transferable to automobile parts?</p>
</sec>
<sec id="s3-5">
<title>3.5 Architecture considerations: Can low-cost authentication work for automobile parts?</title>
<p>Many automobile parts have serial numbers or batch numbers. The $100 currency has a serial number and fingerprint features. The coffee bean bag has a QR code and logged mass and moisture content. Is a trust anchor possible for installed automobile parts, parts not directly connected to the vehicle communication bus? Will this trust anchor have a uniqueness somewhere between currency print features and coffee bean bag mass and moisture content? The search space and procedure are.<list list-type="simple">
<list-item>
<p>1. A unique physical property of the potentially counterfeited part;</p>
</list-item>
<list-item>
<p>2. After the part is installed on the vehicle, the part can be linked to a vehicle sensor;</p>
</list-item>
<list-item>
<p>3. The signal detected by the vehicle sensor can be converted to a perceptual hash;</p>
</list-item>
<list-item>
<p>4. The perceptual hash is uploaded by smart contract and compared with a reference perceptual hash secured on a private blockchain; and</p>
</list-item>
<list-item>
<p>5. The hash comparison yields a probability of part authenticity.</p>
</list-item>
</list>We note that many of the parts that are both subject to counterfeiting and also not directly connected to the vehicle communication bus are parts that move. In general, moving parts emit an acoustic signature. One of the authors is on the faculty of the US Naval Academy and the detection and identification of acoustic signatures is a core expertise of the Navy.</p>
</sec>
<sec id="s3-6">
<title>3.6 Architecture options: Sensors</title>
<p>Automobiles today have a number of embedded devices, sensors, and features. Many of the features are supported by embedded software and electronic control units (ECUs). Luxury cars like Mercedes Benz and Lexus can have over 100 ECUs<xref ref-type="fn" rid="fn14">
<sup>14</sup>
</xref> Other examples of embedded devices and systems in automobiles are ignition systems, antilock braking systems, and airbag control units. The integration of these embedded devices and sensors enable an embedded Internet of Things (IoT) for vehicles.</p>
<p>An efficient implementation of counterfeit part detection will benefit from leveraging the IoT structure associated with connected and autonomous vehicles. In return, autonomous vehicles containing only authentic parts are judged to be more reliable participants in the network. Sensors, data capture and storage mechanisms, and wireless communications can help in tracking automotive parts with proper authentication and security features.</p>
<p>One of the authors of this paper is a chemist and would like to point out the availability of sensors covering a wide range of chemical and material properties. The scientific instruction supply company Vernier Science Education has a website showing sensors for pH, optical spectroscopy, magnetic field, radiation, gas chromatography, polarimetry, moisture, salinity, acoustics and more.<xref ref-type="fn" rid="fn15">
<sup>15</sup>
</xref> This is not a commercial recommendation for this vendor, but is given for the purpose of illustration. These sensors, with corresponding controllers, can increase the range of physical properties measured by embedded sensors. For example, acoustical sensors can be used to track physical items. In ecology, distributed networks of acoustical sensors are used to track and identify insects and bats (<xref ref-type="bibr" rid="B32">Phung et al., 2017</xref>; <xref ref-type="bibr" rid="B16">Gallacher et al., 2021</xref>). The data processing has characteristics of the <italic>Shazam</italic> app, with Fourier transforms of short time windows and classification operations (<xref ref-type="bibr" rid="B36">Swierczek, 2005</xref>; <xref ref-type="bibr" rid="B32">Phung et al., 2017</xref>).</p>
<p>With regard to IoT sensors, automobile repair parts can be separated into those parts connected to the vehicle computer network&#x2014;ECM, airbags, information panel, and door locks&#x2014;and those parts isolated from the computer network&#x2014;brake pads, windscreen, and tires. The former can be authenticated by established methods of embedded digital codes which are queried by the vehicle&#x2019;s computer system. The latter, parts isolated from the computer network, are more challenging and are the subject of this paper. In the next section, we will explore the adaptation of the coffee bean model onto detection of counterfeit tires based on an acoustical signature.</p>
</sec>
</sec>
<sec id="s4">
<title>4 Tires and embedded internet-of-things: Two options</title>
<sec id="s4-1">
<title>4.1 RFID in automobile tires: Patents</title>
<p>In March 2022, Bridgestone Corporation was awarded US patent 1,288,628 B2 with an abstract describing a digital tag mounted in a tire and the validation procedure (<xref ref-type="bibr" rid="B39">Yamada et al., 2022</xref>). An earlier patent described the physical mounting of an RFID tag in a tire, but with less detail on the validation procedure (<xref ref-type="bibr" rid="B6">Bracq and Lauragais, 2020</xref>). Bridgestone has announced implementation of RFID tags for Gran Touring race car tires.<xref ref-type="fn" rid="fn16">
<sup>16</sup>
</xref> Let us look at the Bridgestone patent from the point of view of the $100 currency trust anchors and the coffee bean supply chain. What are the strengths and weaknesses of the Bridgestone patent?</p>
<p>&#x201c;An information presentation system includes an information presentation apparatus, a transmitter attached to a tire and configured to transmit tire ID information for identifying the tire, and a database configured to store tire ID information of tires which are genuine products, and the information presentation apparatus includes a reader configured to perform near field communication with the transmitter, to acquire the tire ID information transmitted by the transmitter, and a controller configured to cause an information presenter to present information indicating that the tire identified with the tire ID information is a genuine product in a case where the tire ID information is stored in the database, and/or cause the information presenter to present information indicating that the tire identified with the tire ID information is a counterfeit product in a case where the tire ID information is not stored in the database.&#x201d; (<xref ref-type="bibr" rid="B39">Yamada et al., 2022</xref>).</p>
<p>For the purpose of this discussion, we will assume the Bridgestone patent describes.<list list-type="simple">
<list-item>
<p>&#x2022; A full-featured RFID tag with secure authentication,</p>
</list-item>
<list-item>
<p>&#x2022; A secure database, and</p>
</list-item>
<list-item>
<p>&#x2022; A handheld RFID reader not integral with the vehicle.</p>
</list-item>
</list>
</p>
<p>First, we note the impressive capabilities of passive RFID tags (<xref ref-type="bibr" rid="B27">Landaluce et al., 2020</xref>), security (<xref ref-type="bibr" rid="B18">Good and Benaissa, 2013</xref>), and the further development of features such as privacy (<xref ref-type="bibr" rid="B10">Ding et al., 2022</xref>). In addition to the RFID, tires have a identifying production number that gives manufacture, location, week, and year of production.<xref ref-type="fn" rid="fn17">
<sup>17</sup>
</xref> The tire identification number (TIN) is not as unique as a serial number, but instead identifies a batch of tires. The TIN is plainly visible on the tire sidewall. The patent also mentions using photography of the tread pattern to match against the RFID. In summary, the Bridgestone patent describes an effective process to establish tire authenticity in the shop.</p>
<p>However, an authentic tire in the shop does not mean an authentic tire is installed on the vehicle. For comparison, as a bank accepts $100 currency, authenticity is checked by the bank at the time of acceptance of the currency. As the coffee bean bags proceed along the supply chain from farmer to the restaurant, the acceptance of the bag is checked by the recipient along the supply chain. We note that a transaction order which schedules authentication <italic>before transfer of ownership</italic> allows fraud.</p>
<p>Another issue is vehicle owner privacy. After the RFID has served its purpose for the supply chain security, how is owner privacy enabled? Can bad actors track people through the tires on their vehicles?</p>
</sec>
<sec id="s4-2">
<title>4.2 The acoustical signature of an installed tire</title>
<p>We propose connecting physical properties of the tire, installed on the vehicle, with a blockchain-secured database. From the sensors listed in <xref ref-type="sec" rid="s3-6">Section 3.6</xref>, an acoustic sensor is a logical first choice. Then as described for the coffee bean supply chain in <xref ref-type="sec" rid="s3-4">Section 3.4</xref>, the cryptographic hash is generated from the tire identification number and the perceptual hash is generated from the acoustic signature of the tire. The calculation of part authenticity is based on the distance of the new perceptual hash <italic>versus</italic> the reference perceptual hash.</p>
<p>The term acoustic signature is used to describe a combination of acoustic emissions of sound emitters, such as those of ships, submarines, aircraft, machinery, animals, and music which can be used for identification, condition, behavior, and physical location. For music, the popular <italic>Shazam</italic> application readily identifies music from just a few seconds of audio data. Similarly, the acoustic signature of a tire, as shown in <xref ref-type="fig" rid="F6">Figure 6</xref>, is rich in detail with the potential of generating a fingerprint with sufficient uniqueness to meet part authentication needs.The acoustic features that one looks for include acoustical power at well-spaced frequencies, as shown in <xref ref-type="fig" rid="F6">Figure 6</xref>. Another useful characteristic is the ability to modulate the signal; in the case of tire noise, modulation is possible with a defined acceleration-deceleration profile. The combination of resolvable frequencies and their response to external modulation creates a signal pattern than can be converted into a perceptual hash. In an N-dimensional hash space, the objective are hashes from new tires of the same batch that are clustered and well separated from hashes derived from tires of either a different batch or counterfeit.</p>
<fig id="F6" position="float">
<label>FIGURE 6</label>
<caption>
<p>A proposed unique fingerprint of a tire based on acoustic signature. Pirelli tire on Fiat 500, GoPro Hero3 with suction cup mount.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g006.tif"/>
</fig>
<p>A draft validation app, akin to the Toks Coffee Tracking app shown in <xref ref-type="fig" rid="F5">Figure 5</xref>, is outlined in <xref ref-type="fig" rid="F7">Figure 7</xref>. The table shows the physical item, its characteristic features, and the logging of the cyber-physical trust anchor with blockchain.</p>
<fig id="F7" position="float">
<label>FIGURE 7</label>
<caption>
<p>A proposed tire validation app modeled after the Toks Coffee Tracking app. The last line is key: part authenticity is calculated based on features measured by the car with the tire mounted on the car.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g007.tif"/>
</fig>
<p>Relative to the Bridgestone patent, the use of an acoustical signature has the capital equipment cost of additional microphones in the vehicle; noise isolation in the vehicle will likely prevent the microphone in the steering wheel from measuring tire noise with sufficient fidelity. On the other hand, the authenticity is established for the installed tire, not just the tire in the shop. Because the perceptual hash is a one-way function, the acoustical noise signature cannot be regenerated from a captured hash. Roadside microphones cannot use the perceptual hash to identify a vehicle. Thus, the owner privacy is preserved.</p>
<p>When do you allow the cloud to know where your car is? While advances in technology enhance safety and convenience, the technology also generates a significant amount of sensitive or personal vehicle data, such as location (<xref ref-type="bibr" rid="B18">Good and Benaissa, 2013</xref>; <xref ref-type="bibr" rid="B41">Zhang et al., 2022</xref>) With respect to privacy, a non-connected car currently allows location to be known under two conditions. One involves utilizing devices that are distinct from the automobile. Another requires historical information linking a VIN to location, such as maintenance records or CARFAX reports. In connected and autonomous networks, GPS and other sensors collect real-time location data, which can be compromised if connectivity includes cloud based applications (i.e., infotainment). Automated counterfeit detection systems in vehicles require privacy considerations. We incorporate hashing as a means to preserve privacy in connected and autonomous vehicle networks.</p>
</sec>
<sec id="s4-3">
<title>4.3 Proposed architecture</title>
<p>A proposed architecture is shown in <xref ref-type="fig" rid="F8">Figure 8</xref>. A key component of the TIN/acoustics cyber-physical trust anchor architecture is tire-to-vehicle authentication via an acoustical cyber-physical trust anchor. The on-vehicle authentication reduces a potential attack vector in which the customer is shown an authentic tire in the salesroom, but the mechanic, working out-of-sight of the customer, installs a counterfeit tire.</p>
<fig id="F8" position="float">
<label>FIGURE 8</label>
<caption>
<p>Two proposed architectures for car tire supply chain security. The top row shows TIN/RFID enables security to the salesroom, whilst the bottom row with TIN/acoustics preserves security through tire installation and demonstrates tire authentication to the vehicle OBD-II/EOBD on-board diagnostics network and vehicle-to-infrastructure (V2X) network. TIN is the human-readable tire identification number printed on the tire showing batch production information. The doubleheaded arrows show usage of the cyber-physical trust anchor to validate authentication and record provenance with the blockchain.</p>
</caption>
<graphic xlink:href="frcmn-04-1096841-g008.tif"/>
</fig>
</sec>
</sec>
<sec sec-type="conclusion" id="s5">
<title>5 Conclusion</title>
<p>Embedded sensors from the Internet of Things can be applied to vehicle parts not directly connected to the vehicle&#x2019;s communication bus. Then, a cyber-physical trust anchor can be established and used to verify part authenticity. The workload of secure supply chain development can be shared with the development of the autonomous vehicle networks, as the fleet performance is degraded by vehicles with questionable repair parts of uncertain reliability.</p>
<p>This manuscript develops the key parameters for a low-cost part authentication strategy. First, there is the cyber-physical trust anchor.<list list-type="simple">
<list-item>
<p>&#x2022; A serial number converted to a cryptographic hash,</p>
</list-item>
<list-item>
<p>&#x2022; Unique features or physical properties converted to a perceptual hash,</p>
</list-item>
<list-item>
<p>&#x2022; A database secured by blockchain, and</p>
</list-item>
<list-item>
<p>&#x2022; A truth table and thresholds for hash distances developed to report probability of part authenticity.</p>
</list-item>
</list>
</p>
<p>Second, the readout of the print features or physical properties is recommended <italic>after installation</italic> of the part onto the vehicle. This is challenging for those parts not normally connected to the vehicle communication network. To address this challenge, alternative IoT sensors are devised. For moving parts such as tires, motion will generate an acoustical signature. Herein, we propose investigation of tire noise, the reduction of tire noise to a perceptual hash, and the comparison of the measured hash <italic>versus</italic> a reference hash secured by blockchain to leading to the calculation of the probability of part authenticity.</p>
<p>Third, the financial incentives are both carrot and stick. The secure supply chain yields market recovery for the tire manufacturer. There is also a financial incentive from a policy, yet to be developed, for participation of vehicles in an autonomous vehicle network. Only vehicles participating in secure supply chain processes, such as described herein for tires, should be allowed to participate in autonomous vehicle network. Vehicles not participating in a secure supply chain process to ensure authentic repair parts are used in vehicle repair should not be allowed to participate in the autonomous vehicle network. The risk to the other vehicles in the network is unacceptable.</p>
</sec>
</body>
<back>
<sec sec-type="data-availability" id="s7">
<title>Data availability statement</title>
<p>The original contributions presented in the study are included in the article/Supplementary material, further inquiries can be directed to the corresponding author.</p>
</sec>
<sec id="s8">
<title>Author contributions</title>
<p>MM evaluted the cyber security assessment and the magnitude of the counterfeit problem. LB provided the perspective of a chemist and former mechanic. IT provided the expertise on blockchain and the secure coffee bean supply chain. All authors contributed to the article and approved the submitted version.</p>
</sec>
<ack>
<p>We gratefully acknowledge the support of the National Institute of Standards and Technology, U.S. Department of Commerce in providing the SBIR support for this project, as well as the U.S. National Science Foundation under grant number OIA-1946231, the Louisiana Board of Regents for the Louisiana Materials Design Alliance (LAMDA), and the U.S. Naval Academy.We thank Commander Brien Croteau for bringing the Frontiers special issue on Embedded Systems and Network Security to our attention.</p>
</ack>
<sec sec-type="COI-statement" id="s9">
<title>Conflict of interest</title>
<p>Author IT is employed by SIMBA Chain, Inc. Author LB is a co-founder of Refined Imaging.</p>
<p>The remaining author declares that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="disclaimer" id="s10">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<sec id="s6">
<title>Author disclaimer</title>
<p>The views expressed in this article do not necessarily represent the views or opinions of the U. S. Naval Academy, Department of the Navy, or Department of Defense (DoD) or any of its components.</p>
</sec>
<fn-group>
<fn id="fn1">
<label>1</label>
<p>Millions of Lines of Code, <ext-link ext-link-type="uri" xlink:href="https://informationisbeautiful.net/visualizations/million-lines-of-code/">https://informationisbeautiful.net/visualizations/million-lines-of-code/</ext-link>
</p>
</fn>
<fn id="fn2">
<label>2</label>
<p>Counterfeit Goods: A Danger to Public Safety. <ext-link ext-link-type="uri" xlink:href="https://www.ice.gov/features/dangers-counterfeit-items">https://www.ice.gov/features/dangers-counterfeit-items</ext-link>
</p>
</fn>
<fn id="fn3">
<label>3</label>
<p>The 4 Most Common Counterfeit Products. <ext-link ext-link-type="uri" xlink:href="https://nabcore.com/top-4-most-common-counterfeited-products/">https://nabcore.com/top-4-most-common-counterfeited-products/</ext-link>
</p>
</fn>
<fn id="fn4">
<label>4</label>
<p>Toyoto Australia sting finds parts purchased online are often fake. <ext-link ext-link-type="uri" xlink:href="https://www.drive.com.au/news/counterfeit-car-parts-renewed-warnings-after-an-increase-in-busts/">https://www.drive.com.au/news/counterfeit-car-parts-renewed-warnings-after-an-increase-in-busts/</ext-link>
</p>
</fn>
<fn id="fn5">
<label>5</label>
<p>Commonly counterfeited automotive components. <ext-link ext-link-type="uri" xlink:href="https://a2c2.com/resources">https://a2c2.com/resources</ext-link>
</p>
</fn>
<fn id="fn6">
<label>6</label>
<p>Jeep Hacking 101: <ext-link ext-link-type="uri" xlink:href="https://spectrum.ieee.org/jeep-hacking-101\#toggle-gdpr">https://spectrum.ieee.org/jeep-hacking-101\&#x23;toggle-gdpr</ext-link>
</p>
</fn>
<fn id="fn7">
<label>7</label>
<p>ACDelco, General Motors, <ext-link ext-link-type="uri" xlink:href="https://www.acdelco.com/content/dam/acdelco/na/us/en/index/counterfeit-parts/02-pdfs/acdelco-counterfeit-article.pdf">https://www.acdelco.com/content/dam/acdelco/na/us/en/index/counterfeit-parts/02-pdfs/acdelco-counterfeit-article.pdf</ext-link>, (accessed: 04.04.2021)</p>
</fn>
<fn id="fn8">
<label>8</label>
<p>Toyota Tacloban, Leyte, Inc., Leyte, Philippines, <ext-link ext-link-type="uri" xlink:href="https://toyotatacloban.com/toyota-genuine-parts">https://toyotatacloban.com/toyota-genuine-parts</ext-link>
</p>
</fn>
<fn id="fn9">
<label>9</label>
<p>SAE Aerospace Standard (AS) AS6171 <ext-link ext-link-type="uri" xlink:href="https://www.sae.org/standards/content/as6171/">https://www.sae.org/standards/content/as6171/</ext-link>
</p>
</fn>
<fn id="fn10">
<label>10</label>
<p>NIST.IR 8419 &#x201c;Blockchain and Related Technologies to Support Manufacturing Supply Chain Traceability: Needs and Industry Perspectives&#x201d;, <ext-link ext-link-type="uri" xlink:href="https://csrc.nist.gov/publications/detail/nistir/8419/final">https://csrc.nist.gov/publications/detail/nistir/8419/final</ext-link>
</p>
</fn>
<fn id="fn11">
<label>11</label>
<p>U.S. Currency Education Program. <ext-link ext-link-type="uri" xlink:href="https://www.uscurrency.gov/denominations/100">https://www.uscurrency.gov/denominations/100</ext-link>
</p>
</fn>
<fn id="fn12">
<label>12</label>
<p>Tacan&#xe1; Natural Reserve, <ext-link ext-link-type="uri" xlink:href="https://en.wikipedia.org/wiki/Volcn_Tacan_Biosphere_Reserve">https://en.wikipedia.org/wiki/Volcn_Tacan_Biosphere_Reserve</ext-link>
</p>
</fn>
<fn id="fn13">
<label>13</label>
<p>Dr. Ian Taylor&#x2019;s lecture on blockchain and the coffee bean supply chain. <ext-link ext-link-type="uri" xlink:href="https://www.youtube.com/watch?v=DWjP8Igox1o">https://www.youtube.com/watch?v&#x3d;DWjP8Igox1o</ext-link>
</p>
</fn>
<fn id="fn14">
<label>14</label>
<p>From Silicon to Software <ext-link ext-link-type="uri" xlink:href="https://blogs.synopsys.com/from-silicon-to-software/2021/05/20/ecu-automotive-cybersecurity/">https://blogs.synopsys.com/from-silicon-to-software/2021/05/20/ecu-automotive-cybersecurity/</ext-link>
</p>
</fn>
<fn id="fn15">
<label>15</label>
<p>Vernier Science Education, <ext-link ext-link-type="uri" xlink:href="https://www.vernier.com/product-category/?category=sensors">https://www.vernier.com/product-category/?category&#x3d;sensors</ext-link>
</p>
</fn>
<fn id="fn16">
<label>16</label>
<p>Rain Alliance, 31 October 2022: <ext-link ext-link-type="uri" xlink:href="https://rainrfid.org/bridgestone-japan-selects-avery-dennison-maxdura-tire-tags/">https://rainrfid.org/bridgestone-japan-selects-avery-dennison-maxdura-tire-tags/</ext-link>
</p>
</fn>
<fn id="fn17">
<label>17</label>
<p>Tire Identification and Recordkeeping: <ext-link ext-link-type="uri" xlink:href="https://www.federalregister.gov/documents/2015/04/13/2015-08418/tire-identification-and-recordkeeping">https://www.federalregister.gov/documents/2015/04/13/2015&#x2013;08418/tire-identification-and-recordkeeping</ext-link>
</p>
</fn>
</fn-group>
<ref-list>
<title>References</title>
<ref id="B1">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Acharya</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Dvorkin</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Pandzic</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Karri</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Cybersecurity of smart electric vehicle charging: a power grid perspective</article-title>. <source>IEEE Access</source> <volume>8</volume>, <fpage>214434</fpage>&#x2013;<lpage>214453</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2020.3041074</pub-id>
</citation>
</ref>
<ref id="B2">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Aliwa</surname>
<given-names>E.</given-names>
</name>
<name>
<surname>Rana</surname>
<given-names>O.</given-names>
</name>
<name>
<surname>Perera</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Burnap</surname>
<given-names>P.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Cyberattacks and countermeasures for in-vehicle networks</article-title>. <source>ACM Comput. Surv.</source> <volume>54</volume>, <fpage>1</fpage>&#x2013;<lpage>37</lpage>. <pub-id pub-id-type="doi">10.1145/3431233</pub-id>
</citation>
</ref>
<ref id="B3">
<citation citation-type="confproc">
<person-group person-group-type="author">
<name>
<surname>Anastasiadis</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Moschou</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Livitckaia</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Votis</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Tzovaras</surname>
<given-names>D.</given-names>
</name>
</person-group> (<year>2023</year>). &#x201c;<article-title>A novel high-interaction honeypot network for internet of vehicles</article-title>,&#x201d; in <conf-name>2023 31st Mediterranean Conference on Control and Automation (MED)</conf-name>, <conf-loc>Limassol</conf-loc>, <conf-date>June 26 &#x2013; 29, 2023</conf-date>, <fpage>281</fpage>. <comment>&#x2013;286</comment>. <pub-id pub-id-type="doi">10.1109/MED59994.2023.10185669</pub-id>
</citation>
</ref>
<ref id="B4">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Baldo</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Bianchi</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Conti</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Trevisan</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Turrin</surname>
<given-names>F.</given-names>
</name>
</person-group> (<year>2023</year>). <source>HoneyEVSE: an honeypot to emulate electric vehicle supply equipments</source>. <comment>
<italic>arXiv</italic> doi</comment>. <pub-id pub-id-type="doi">10.48550/arXiv.2309.06077</pub-id>
</citation>
</ref>
<ref id="B5">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Benyahya</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Collen</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Nijdam</surname>
<given-names>N. A.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>Analyses on standards and regulations for connected and automated vehicles: identifying the certifications roadmap</article-title>. <source>Transp. Eng.</source> <volume>14</volume>, <fpage>100205</fpage>. <pub-id pub-id-type="doi">10.1016/j.treng.2023.100205</pub-id>
</citation>
</ref>
<ref id="B6">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Bracq</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Lauragais</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2020</year>). <source>LDL technology, assignee. Method for managing type identifiers</source>. <comment>Tech. Rep. United States patent US10682892 B2</comment>. <publisher-loc>France</publisher-loc>: <publisher-name>LDL Technology</publisher-name>.</citation>
</ref>
<ref id="B7">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Chen</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Romanowich</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Castillo</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Roy</surname>
<given-names>K. C.</given-names>
</name>
<name>
<surname>Chavez</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Xu</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>ExHPD: exploiting human, physical, and driving behaviors to detect vehicle cyber attacks</article-title>. <source>IEEE Internet Things J.</source> <volume>8</volume>, <fpage>14355</fpage>&#x2013;<lpage>14371</lpage>. <pub-id pub-id-type="doi">10.1109/JIOT.2021.3069951</pub-id>
</citation>
</ref>
<ref id="B8">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Chen</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Shiwakoti</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Stasinopoulos</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Khan</surname>
<given-names>S. K.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>State-of-the-Art of factors affecting the adoption of automated vehicles</article-title>. <source>Sustainability</source> <volume>14</volume>, <fpage>6697</fpage>. <pub-id pub-id-type="doi">10.3390/su14116697</pub-id>
</citation>
</ref>
<ref id="B9">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Cheung</surname>
<given-names>K.-F.</given-names>
</name>
<name>
<surname>Bell</surname>
<given-names>M. G.</given-names>
</name>
<name>
<surname>Bhattacharjya</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Cybersecurity in logistics and supply chain management: an overview and future research directions</article-title>. <source>Transp. Res. Part E Logist. Transp. Rev.</source> <volume>146</volume>, <fpage>102217</fpage>. <pub-id pub-id-type="doi">10.1016/j.tre.2020.102217</pub-id>
</citation>
</ref>
<ref id="B10">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Ding</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Han</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Zhao</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Xi</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Jiang</surname>
<given-names>Z.</given-names>
</name>
<etal/>
</person-group> (<year>2022</year>). <article-title>Arbitrator2.0: preventing unauthorized access on passive tags</article-title>. <source>IEEE Trans. Mob. Comput.</source> <volume>21</volume>, <fpage>835</fpage>&#x2013;<lpage>848</lpage>. <pub-id pub-id-type="doi">10.1109/TMC.2020.3017484</pub-id>
</citation>
</ref>
<ref id="B11">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Elgazzar</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Khalil</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Alghamdi</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Badr</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Abdelkader</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Elewah</surname>
<given-names>A.</given-names>
</name>
<etal/>
</person-group> (<year>2022</year>). <article-title>Revisiting the internet of things: new trends, opportunities and grand challenges</article-title>. <source>Front. Internet Things</source> <volume>1</volume>, <fpage>1073780</fpage>. <pub-id pub-id-type="doi">10.3389/friot.2022.1073780</pub-id>
</citation>
</ref>
<ref id="B12">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Elkhail</surname>
<given-names>A. A.</given-names>
</name>
<name>
<surname>Refat</surname>
<given-names>R. U. D.</given-names>
</name>
<name>
<surname>Habre</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Hafeez</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Bacha</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Malik</surname>
<given-names>H.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Vehicle security: a survey of security issues and vulnerabilities, malware attacks and defenses</article-title>. <source>IEEE Access</source> <volume>9</volume>, <fpage>162401</fpage>&#x2013;<lpage>162437</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2021.3130495</pub-id>
</citation>
</ref>
<ref id="B13">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>El-Rewini</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Sadatsharan</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Sugunaraj</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Selvaraj</surname>
<given-names>D. F.</given-names>
</name>
<name>
<surname>Plathottam</surname>
<given-names>S. J.</given-names>
</name>
<name>
<surname>Ranganathan</surname>
<given-names>P.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Cybersecurity attacks in vehicular sensors</article-title>. <source>IEEE Sensors J.</source> <volume>20</volume>, <fpage>13752</fpage>&#x2013;<lpage>13767</lpage>. <pub-id pub-id-type="doi">10.1109/JSEN.2020.3004275</pub-id>
</citation>
</ref>
<ref id="B14">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Feng</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Huang</surname>
<given-names>S. E.</given-names>
</name>
<name>
<surname>Wong</surname>
<given-names>W.</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>Q. A.</given-names>
</name>
<name>
<surname>Mao</surname>
<given-names>Z. M.</given-names>
</name>
<name>
<surname>Liu</surname>
<given-names>H. X.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>On the cybersecurity of traffic signal control system with connected vehicles</article-title>. <source>IEEE Trans. Intelligent Transp. Syst.</source> <volume>23</volume>, <fpage>16267</fpage>&#x2013;<lpage>16279</lpage>. <pub-id pub-id-type="doi">10.1109/TITS.2022.3149449</pub-id>
</citation>
</ref>
<ref id="B15">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Fernandez de Arroyabe</surname>
<given-names>I.</given-names>
</name>
<name>
<surname>Watson</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Angelopoulou</surname>
<given-names>O.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Cybersecurity in the automotive industry: a systematic literature review (slr)</article-title>. <source>J. Comput. Inf. Syst.</source> <volume>1</volume>, <fpage>716</fpage>&#x2013;<lpage>734</lpage>. <pub-id pub-id-type="doi">10.1080/08874417.2022.2103853</pub-id>
</citation>
</ref>
<ref id="B16">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Gallacher</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Wilson</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Fairbrass</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Turmukhambetov</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Firman</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Kreitmayer</surname>
<given-names>S.</given-names>
</name>
<etal/>
</person-group> (<year>2021</year>). <article-title>Shazam for bats: internet of Things for continuous real?time biodiversity monitoring</article-title>. <source>IET Smart Cities</source> <volume>3</volume>, <fpage>171</fpage>&#x2013;<lpage>183</lpage>. <pub-id pub-id-type="doi">10.1049/smc2.12016</pub-id>
</citation>
</ref>
<ref id="B17">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Girdhar</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>You</surname>
<given-names>Y.</given-names>
</name>
<name>
<surname>Song</surname>
<given-names>T.-J.</given-names>
</name>
<name>
<surname>Ghosh</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Hong</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Post-accident cyberattack event analysis for connected and automated vehicles</article-title>. <source>IEEE Access</source> <volume>10</volume>, <fpage>83176</fpage>&#x2013;<lpage>83194</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2022.3196346</pub-id>
</citation>
</ref>
<ref id="B18">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Good</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Benaissa</surname>
<given-names>M.</given-names>
</name>
</person-group> (<year>2013</year>). <article-title>A holistic approach examining RFID design for security and privacy</article-title>. <source>J. Supercomput.</source> <volume>64</volume>, <fpage>664</fpage>&#x2013;<lpage>684</lpage>. <pub-id pub-id-type="doi">10.1007/s11227-010-0497-9</pub-id>
</citation>
</ref>
<ref id="B19">
<citation citation-type="book">
<collab>GS1</collab> (<year>2021</year>). <source>Standards</source>. <comment>Available at: <ext-link ext-link-type="uri" xlink:href="https://www.gs1.org/standards">https://www.gs1.org/standards</ext-link>.</comment>
</citation>
</ref>
<ref id="B20">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Hashem Eiza</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Ni</surname>
<given-names>Q.</given-names>
</name>
</person-group> (<year>2017</year>). <article-title>Driving with sharks: rethinking connected vehicles with vehicle cybersecurity</article-title>. <source>IEEE Veh. Technol. Mag.</source> <volume>12</volume>, <fpage>45</fpage>&#x2013;<lpage>51</lpage>. <pub-id pub-id-type="doi">10.1109/MVT.2017.2669348</pub-id>
</citation>
</ref>
<ref id="B21">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kennedy</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Holt</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Cheng</surname>
<given-names>B.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Automotive cybersecurity: assessing a new platform for cybercrime and malicious hacking</article-title>. <source>J. Crime Justice</source> <volume>42</volume>, <fpage>632</fpage>&#x2013;<lpage>645</lpage>. <pub-id pub-id-type="doi">10.1080/0735648X.2019.1692425</pub-id>
</citation>
</ref>
<ref id="B22">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Khan</surname>
<given-names>S. K.</given-names>
</name>
<name>
<surname>Shiwakoti</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Stasinopoulos</surname>
<given-names>P.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>A conceptual system dynamics model for cybersecurity assessment of connected and autonomous vehicles</article-title>. <source>Accid. Analysis Prev.</source> <volume>165</volume>, <fpage>106515</fpage>. <pub-id pub-id-type="doi">10.1016/j.aap.2021.106515</pub-id>
</citation>
</ref>
<ref id="B23">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Khan</surname>
<given-names>S. K.</given-names>
</name>
<name>
<surname>Shiwakoti</surname>
<given-names>N.</given-names>
</name>
<name>
<surname>Stasinopoulos</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>Cyber-attacks in the next-generation cars, mitigation techniques, anticipated readiness and future directions</article-title>. <source>Accid. Analysis Prev.</source> <volume>148</volume>, <fpage>105837</fpage>. <pub-id pub-id-type="doi">10.1016/j.aap.2020.105837</pub-id>
</citation>
</ref>
<ref id="B24">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kukkala</surname>
<given-names>V. K.</given-names>
</name>
<name>
<surname>Thiruloga</surname>
<given-names>S. V.</given-names>
</name>
<name>
<surname>Pasricha</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Roadmap for cybersecurity in autonomous vehicles</article-title>. <source>IEEE Consum. Electron. Mag.</source> <volume>11</volume>, <fpage>13</fpage>&#x2013;<lpage>23</lpage>. <pub-id pub-id-type="doi">10.1109/MCE.2022.3154346</pub-id>
</citation>
</ref>
<ref id="B25">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Kumar</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Dohare</surname>
<given-names>U.</given-names>
</name>
<name>
<surname>Kumar</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Prasad Dora</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Naseer Qureshi</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Kharel</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2019</year>). <article-title>Cybersecurity measures for geocasting in vehicular cyber physical system environments</article-title>. <source>IEEE Internet Things J.</source> <volume>6</volume>, <fpage>5916</fpage>&#x2013;<lpage>5926</lpage>. <pub-id pub-id-type="doi">10.1109/JIOT.2018.2872474</pub-id>
</citation>
</ref>
<ref id="B26">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Labrado</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Thapliyal</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Mohanty</surname>
<given-names>S. P.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Fortifying vehicular security through low overhead physically unclonable functions</article-title>. <source>ACM J. Emerg. Technol. Comput. Syst.</source> <volume>18</volume>, <fpage>1</fpage>&#x2013;<lpage>18</lpage>. <pub-id pub-id-type="doi">10.1145/3442443</pub-id>
</citation>
</ref>
<ref id="B27">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Landaluce</surname>
<given-names>H.</given-names>
</name>
<name>
<surname>Arjona</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Perallos</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Falcone</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Angulo</surname>
<given-names>I.</given-names>
</name>
<name>
<surname>Muralter</surname>
<given-names>F.</given-names>
</name>
</person-group> (<year>2020</year>). <article-title>A review of IoT sensing applications and challenges using RFID and wireless sensor networks</article-title>. <source>Sensors</source> <volume>20</volume>, <fpage>2495</fpage>. <pub-id pub-id-type="doi">10.3390/s20092495</pub-id>
</citation>
</ref>
<ref id="B28">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lin</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Shi</surname>
<given-names>Q.</given-names>
</name>
<name>
<surname>Zhou</surname>
<given-names>N.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Construction of a traceability system for food industry chain safety information based on internet of things technology</article-title>. <source>Front. Public Health</source> <volume>10</volume>, <fpage>857039</fpage>. <pub-id pub-id-type="doi">10.3389/fpubh.2022.857039</pub-id>
</citation>
</ref>
<ref id="B29">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Lv</surname>
<given-names>Z.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Practical application of internet of things in the creation of intelligent services and environments</article-title>. <source>Front. Internet Things</source> <volume>1</volume>, <fpage>912388</fpage>. <pub-id pub-id-type="doi">10.3389/friot.2022.912388</pub-id>
</citation>
</ref>
<ref id="B30">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Mabad</surname>
<given-names>T.</given-names>
</name>
<name>
<surname>Ali</surname>
<given-names>O.</given-names>
</name>
<name>
<surname>Ally</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Wamba</surname>
<given-names>S. F.</given-names>
</name>
<name>
<surname>Chan</surname>
<given-names>K. C.</given-names>
</name>
</person-group> (<year>2021</year>). <article-title>Making investment decisions on RFID technology: an evaluation of key adoption factors in construction firms</article-title>. <source>IEEE Access</source> <volume>9</volume>, <fpage>36937</fpage>&#x2013;<lpage>36954</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2021.3063301</pub-id>
</citation>
</ref>
<ref id="B31">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Panda</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Rass</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Moschoyiannis</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Liang</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Loukas</surname>
<given-names>G.</given-names>
</name>
<name>
<surname>Panaousis</surname>
<given-names>E.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>HoneyCar: a framework to configure honeypot vulnerabilities on the internet of vehicles</article-title>. <source>IEEE Access</source> <volume>10</volume>, <fpage>104671</fpage>&#x2013;<lpage>104685</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2022.3210117</pub-id>
</citation>
</ref>
<ref id="B32">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Phung</surname>
<given-names>Q. V.</given-names>
</name>
<name>
<surname>Ahmad</surname>
<given-names>I.</given-names>
</name>
<name>
<surname>Habibi</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Hinckley</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2017</year>). <article-title>Automated insect detection using acoustic features based on sound generated from insect activities</article-title>. <source>Acoust. Aust.</source> <volume>45</volume>, <fpage>445</fpage>&#x2013;<lpage>451</lpage>. <pub-id pub-id-type="doi">10.1007/s40857-017-0095-6</pub-id>
</citation>
</ref>
<ref id="B33">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Rose</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Borchert</surname>
<given-names>O.</given-names>
</name>
<name>
<surname>Mitchell</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Connelly</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2020</year>). <source>Zero trust architecture</source>. <comment>Tech. rep.</comment> <publisher-loc>United States</publisher-loc>: <publisher-name>National Institute of Standards and Technology</publisher-name>. <pub-id pub-id-type="doi">10.6028/NIST.SP.800-207</pub-id>
</citation>
</ref>
<ref id="B34">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Sharma</surname>
<given-names>P.</given-names>
</name>
<name>
<surname>Gillanders</surname>
<given-names>J.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Cybersecurity and forensics in connected autonomous vehicles: a review of the state-of-the-art</article-title>. <source>IEEE Access</source> <volume>10</volume>, <fpage>108979</fpage>&#x2013;<lpage>108996</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2022.3213843</pub-id>
</citation>
</ref>
<ref id="B35">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Shen</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Turner</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Antonopoulos</surname>
<given-names>G.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Driven to death: a Chinese case study on the counterfeiting of automotive components</article-title>. <source>Asian J. Criminol.</source> <volume>17</volume>, <fpage>311</fpage>&#x2013;<lpage>329</lpage>. <pub-id pub-id-type="doi">10.1007/s11417-022-09365-8</pub-id>
</citation>
</ref>
<ref id="B36">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Swierczek</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2005</year>). <source>Music identification system</source>. <comment>Tech. Rep. United States patent US6,941,275 B1</comment>.</citation>
</ref>
<ref id="B37">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Syed</surname>
<given-names>N. F.</given-names>
</name>
<name>
<surname>Shah</surname>
<given-names>S. W.</given-names>
</name>
<name>
<surname>Shaghaghi</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Anwar</surname>
<given-names>A.</given-names>
</name>
<name>
<surname>Baig</surname>
<given-names>Z.</given-names>
</name>
<name>
<surname>Doss</surname>
<given-names>R.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>Zero trust architecture (zta): a comprehensive survey</article-title>. <source>IEEE Access</source> <volume>10</volume>, <fpage>57143</fpage>&#x2013;<lpage>57179</lpage>. <pub-id pub-id-type="doi">10.1109/ACCESS.2022.3174679</pub-id>
</citation>
</ref>
<ref id="B38">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Wamba</surname>
<given-names>S. F.</given-names>
</name>
<name>
<surname>Chatfield</surname>
<given-names>A. T.</given-names>
</name>
</person-group> (<year>2009</year>). <article-title>A contingency model for creating value from RFID supply chain network projects in logistics and manufacturing environments</article-title>. <source>Eur. J. Inf. Syst.</source> <volume>18</volume>, <fpage>615</fpage>&#x2013;<lpage>636</lpage>. <pub-id pub-id-type="doi">10.1057/ejis.2009.44</pub-id>
</citation>
</ref>
<ref id="B39">
<citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname>Yamada</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Hirajima</surname>
<given-names>S.</given-names>
</name>
<name>
<surname>Yamaguchi</surname>
<given-names>S.</given-names>
</name>
</person-group> (<year>2022</year>). <source>Bridgestone, assignee. Information presentation system, information presentation apparatus, and information presentation method</source>. <comment>Tech. Rep. United States patent US11288628</comment>. <publisher-loc>Japan</publisher-loc>: <publisher-name>Bridgestone Corporation</publisher-name>.</citation>
</ref>
<ref id="B40">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zelle</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Plappert</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Rieke</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Scheuermann</surname>
<given-names>D.</given-names>
</name>
<name>
<surname>Krau&#xdf;</surname>
<given-names>C.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>ThreatSurf: a method for automated Threat Surface assessment in automotive cybersecurity engineering</article-title>. <source>Microprocess. Microsystems</source> <volume>90</volume>, <fpage>104461</fpage>. <pub-id pub-id-type="doi">10.1016/j.micpro.2022.104461</pub-id>
</citation>
</ref>
<ref id="B41">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Zhu</surname>
<given-names>L.</given-names>
</name>
<name>
<surname>Xu</surname>
<given-names>C.</given-names>
</name>
<name>
<surname>Sharif</surname>
<given-names>K.</given-names>
</name>
<name>
<surname>Lu</surname>
<given-names>R.</given-names>
</name>
<name>
<surname>Chen</surname>
<given-names>Y.</given-names>
</name>
</person-group> (<year>2022</year>). <article-title>APPB: anti-counterfeiting and privacy-preserving blockchain-based vehicle supply chains</article-title>. <source>IEEE Trans. Veh. Technol.</source> <volume>71</volume>, <fpage>13152</fpage>&#x2013;<lpage>13164</lpage>. <pub-id pub-id-type="doi">10.1109/TVT.2022.3196051</pub-id>
</citation>
</ref>
<ref id="B42">
<citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname>Zhang</surname>
<given-names>F.</given-names>
</name>
<name>
<surname>Wang</surname>
<given-names>M.</given-names>
</name>
<name>
<surname>Parker</surname>
<given-names>J.</given-names>
</name>
<name>
<surname>Roberts</surname>
<given-names>S. C.</given-names>
</name>
</person-group> (<year>2023</year>). <article-title>The effect of driving style on responses to unexpected vehicle cyberattacks</article-title>. <source>Safety</source> <volume>9</volume>, <fpage>5</fpage>. <pub-id pub-id-type="doi">10.3390/safety9010005</pub-id>
</citation>
</ref>
</ref-list>
</back>
</article>