CAST-SecOC: A Configuration-Aware Multidimensional Testing Method for AUTOSAR SecOC over CAN FD
Yaozong Xu, Cong Wang, Maode MaAUTOSAR Secure Onboard Communication (SecOC) protects in-vehicle messages through authentication, freshness verification, and application-delivery gating, but deployment security also depends on configuration and receiver-state handling. This paper presents CAST-SecOC, a configuration-aware multidimensional testing method for SecOC over Controller Area Network with Flexible Data-Rate (CAN FD). The method jointly models message semantics, observable receiver conditions, freshness relations, configuration parameters, perturbation operators, requirement-level oracles, and traceable evidence. A prototype campaign produced 1575 execution records from 315 retained semantic equivalence classes. None of the 1249 invalid messages reached the application, while all 286 valid messages were eventually delivered; under high load, six of 126 valid messages exceeded their deadlines. Re-scoring the same message-level records with an application-only binary oracle reduced the outcomes to 286 ACCEPT and 1249 REJECT, whereas CAST-SecOC retained six distinct response/timing signatures. Systematic configuration mutation killed 16 of 20 executable non-equivalent mutants, yielding a mutation score of 80.00%. Composed timing-budget analysis showed that Protocol Data Unit PDU-C and PDU-D retained positive headroom at 30% load but insufficient headroom at 85% and 95% load for all three evaluated authenticated-input lengths. The results show that CAST-SecOC provides executable and mechanism-aware evidence for SecOC deployment verification and configuration-fault analysis.