📋 Case Study
Autonomous Haulage System (AHS) Cybersecurity Upgrade – Iron Ore Mine, Pilbara
Legacy CAN bus interfaces exposed to lateral movement; lack of secure firmware update mechanism
🏗️ Project Overview
Deployment of 120 autonomous mining trucks across 3 pits with integrated fleet management system
🎯 Challenge
Legacy CAN bus interfaces exposed to lateral movement; lack of secure firmware update mechanism
🔧 Design Approach
Implementation of hardware-enforced secure boot, CAN-FD gateway with TLS 1.3 tunneling, and air-gapped firmware signing infrastructure
📐 Design Diagram
AI-generated project design illustration
📐 Key Calculations
CAN Bus Attack Surface Reduction
(Original Interfaces − Secured Interfaces) / Original Interfaces × 100
Result: 92%
Quantifies reduction in exploitable endpoints
Firmware Signing Latency
Time from signature to deployment
Result: <4.2 sec
Ensures real-time integrity without operational delay
📊 Results
Zero unauthorized fleet command injection incidents over 18 months; achieved ISA/IEC 62443 SL-3 certification💡 Lessons Learned
- •Hardware-rooted trust anchors are non-negotiable for AHS
- •CAN-FD gateways must be co-located with vehicle ECUs to minimize latency
✅ Key Takeaways
- 1Hardware-rooted trust anchors are non-negotiable for AHS
- 2CAN-FD gateways must be co-located with vehicle ECUs to minimize latency