📋 Case Study

Autonomous Haulage System (AHS) Cybersecurity Upgrade – Iron Ore Mine, Pilbara

Legacy CAN bus interfaces exposed to lateral movement; lack of secure firmware update mechanism

🏗️ Project Overview

Deployment of 120 autonomous mining trucks across 3 pits with integrated fleet management system

🎯 Challenge

Legacy CAN bus interfaces exposed to lateral movement; lack of secure firmware update mechanism

🔧 Design Approach

Implementation of hardware-enforced secure boot, CAN-FD gateway with TLS 1.3 tunneling, and air-gapped firmware signing infrastructure

📐 Design Diagram

Autonomous Haulage System (AHS) Cybersecurity Upgrade Iron Ore Mine, Pilbara | Hardware-Enforced Security Architecture Legacy CAN Bus Exposed interfaces CAN-FD Gateway TLS 1.3 Tunneling Secure Boot Hardware-enforced Air-Gapped Signing Latency: <4.2 sec Attack Surface ↓ 92% reduction CAN Bus Attack Surface Reduction = (Original − Secured)/Original × 100 = 92% Firmware Signing Latency: Signature → Deployment < 4.2 sec

AI-generated project design illustration

📐 Key Calculations

CAN Bus Attack Surface Reduction

(Original Interfaces − Secured Interfaces) / Original Interfaces × 100
Result: 92%
Quantifies reduction in exploitable endpoints

Firmware Signing Latency

Time from signature to deployment
Result: <4.2 sec
Ensures real-time integrity without operational delay

📊 Results

Zero unauthorized fleet command injection incidents over 18 months; achieved ISA/IEC 62443 SL-3 certification

💡 Lessons Learned

  • Hardware-rooted trust anchors are non-negotiable for AHS
  • CAN-FD gateways must be co-located with vehicle ECUs to minimize latency

Key Takeaways

  • 1Hardware-rooted trust anchors are non-negotiable for AHS
  • 2CAN-FD gateways must be co-located with vehicle ECUs to minimize latency