51 | A Security Analysis of the Data Distribution Service (DDS) Protocol
References
1 Object Management Group. (Apr. 2015). “OMG Data Distribution Service (DDS) - 1.4, formal/2015-04-10.” Accessed on Feb.
15, 2022 at https://www.omg.org/spec/DDS-SECURITY/1.1/PDF.
2 Cybersecurity & Infrastructure Security Agency. (Feb. 1, 2022). “ICS Advisory (ICSA-21-315-02): Multiple Data Distribution
Service (DDS) Implementations (Update A).” Accessed on Feb. 15, 2022 at https://www.cisa.gov/uscert/ics/advisories/icsa-
21-315-02.
3 Object Management Group. (2019). “DDS Vendor directory Listing.” Accessed on Feb. 15, 2022 at https://www.omg.org/dds-
directory/vendor/list.htm.
4 Ta-Lun Yen, Federico Maggi, Erik Boasson, Victor Mayoral-vilches, Mars Cheng, Patrick Kuo, and Chizuru Toyama. (Nov.
11, 2021). “The Data Distribution Service (DDS) Protocol is Critical: Let’s Use it Securely!” presented at the Black Hat Europe
Briengs, London. Accessed on Feb. 15, 2022. at https://www.blackhat.com/eu-21/briengs/schedule/index.html#the-data-
distribution-service-dds-protocol-is-critical-lets-use-it-securely-24934.
5 Federico Maggi and Victor Mayoral-Vilches. (Nov. 29, 2021). GitHub. “RTPS contrib layer · Pull Request #3403 · secdev/
scapy.” Accessed on Feb 16, 2022 at https://github.com/secdev/scapy/pull/3403.
6 “Real-time” is used in a generic and non-strict (hard real-time) manner in DDS specications. We were unable to nd timing
guarantees (hard real-time, rm real-time, or soft real-time) provided in any of the reviewed documents. For the purposes of
this research, we conclude that DDS targets remote soft real-time communications at best, leaving rm and hard real-time
interactions to other technologies.
7 Object Management Group. (Apr. 2015). “OMG Data Distribution Service (DDS) - 1.4, formal/2015-04-10.” Accessed on Feb.
15, 2022 at https://www.omg.org/spec/DDS-SECURITY/1.1/PDF.
8 ENISA. (2021). ENISA. “ENISA Threat Landscape 2021.” Accessed on Oct. 2021 at https://www.enisa.europa.eu/publications/
enisa-threat-landscape-2021.
9 UCA International Users Group. (2022). OpenFMB Users. “Open Field Message Bus (OpenFMB).” Accessed on Nov. 29, 2021
at https://openfmb.ucaiug.org/.
10 Kai Richter and Emilio Guijarro Cameros, “AUTOSAR and DDS: A Fresh Approach to Enabling Flexible Vehicle Architectures,”
Mar. 02, 2021. https://www.rti.com/blog/fresh-approach-to-enabling-exible-vehicle-architectures (accessed Nov. 29, 2021).
11 Google. (n.d.). Google. “Protocol Buffers.” Accessed on Feb. 15, 2022 at https://developers.google.com/protocol-buffers.
12 For future security research, recall that complex type systems can be used for type-confusion attacks.
13 Renesas. (Nov. 30, 2021). Renesas. “R-Car H3e-2G & H3 & M3 Starter Kit.” Accessed on Nov. 29, 2021 at https://www.
renesas.com/us/en/products/automotive-products/automotive-system-chips-socs/r-car-h3-m3-starter-kit.
14 Aeronautical Information Manual. (n.d.). FAA. “Section 1. Airport Lighting Aids.” Accessed on January 2021 at https://www.
faa.gov/air_trafc/publications/atpubs/aim_html/chap2_section_1.html.
15 Real-Time Innovations (RTI). (Oct. 22, 2015). Real Time Innovations. “Generic Vehicle Architecture – DDS at the Core.”
Accessed on Nov. 29, 2021 at https://www.slideshare.net/RealTimeInnovations/generic-vehicle-architecture-dds-at-the-core.
16 Johan Scholliers, Pasi Pyykonen, Ari Virtanen, Alina Aittoniemi, Fanny Malin, Maija Federley, and Stella Nikolaou. (2020).
TRA2020 for 8th Transport Research Arena, TRA 2020 - Conference cancelled” in Proceedings of TRA2020, the 8th Transport
Research Arena, Rethinking transport – towards clean and inclusive mobility. “Automated Valet Parking using IoT: Design,
user experience and business opportunities.” Accessed on Nov. 29, 2021 at https://www.tracom./sites/default/les/media/
publication/TRA2020-Book-of-Abstract-Tracom-research-publication.pdf (p.69).
17 ADLINK Tech. (2010). ADLINK Technology. “Coight Consortium Selects Vortex OpenSplice DDS Middleware for Next
Generation European Flight Data Processor.” Accessed Feb. 01, 2022 at https://www.adlinktech.com/en/Coight.
18 Fujitsu. (Mar. 12, 2018). “Fujitsu Accelerates Path to 5G and Conscious Networks with Next-Generation Variable Optical
Transport - Fujitsu United States.” Accessed Dec. 02, 2021 at https://www.fujitsu.com/us/about/resources/news/press-
releases/2018/fnc-20180312.html.
19 UK 5G Innovation Network. (n.d.). “ADLINK Technology.” Accessed on Dec. 2021 at https://uk5g.org/5g-supplier-directory/
adlink-technology/.