Skip to content
AutoST by Zyberum GmbH
Menu
GlossaryAutomotive Ethernet

SOME/IP (Scalable service-Oriented MiddlewarE over IP)

SOME/IP is the AUTOSAR middleware for services on automotive Ethernet: header, methods, events and service discovery. What it is and why exposed services are a finding.

Updated This page as Markdown

In short

SOME/IP (Scalable service-Oriented MiddlewarE over IP) is the AUTOSAR protocol with which ECUs on automotive Ethernet offer and call services: methods with request and response, events and fields. A 16-byte header carries the service and method IDs, a length, client and session IDs and a message type. SOME/IP Service Discovery announces which service instances run where. The protocol provides no authentication of its own, so a node on the network can discover and invoke whatever is offered.

What is SOME/IP?

SOME/IP is a remote procedure call and event protocol for ECUs connected by Ethernet. Each message begins with a 16-byte header: a message ID made of a 16-bit service ID and a 16-bit method ID (method IDs with the top bit set denote events), a 32-bit length that covers the rest of the header plus the payload, a request ID made of a client ID and a session ID, the protocol version 0x01, an interface version, a message type and a return code.

A request to service 0x1234, method 0x0001, with no payload is 12 34 00 01 00 00 00 08 00 01 00 01 01 01 00 00: length 8, client 0x0001, session 0x0001, protocol version 1, interface version 1, message type 00 (REQUEST), return code 00. A normal reply uses message type 0x80; an error reply uses 0x81, and return codes such as 0x02 (unknown service) and 0x03 (unknown method) reveal to a receiver what does and does not exist.

Where is it defined?

AUTOSAR specifies SOME/IP in its Foundation standard, in the SOME/IP protocol specification and the SOME/IP Service Discovery protocol specification, and it is implemented in both the Classic and the Adaptive Platform. There is no ISO standard for it. The threats that bear on it, spoofed messages and unauthorised access to functions, are among those listed for in-vehicle communication in UN R155 Annex 5.

What it means in practice

Because Service Discovery announces offered services to the network, the set of services an ECU exposes is visible to anything that listens. On infotainment and driver-assistance networks the recurring issues are services offered to the whole segment when a single client needs them, methods that run without checking who called, and subscriptions accepted from any address. Each of these widens what a node already on the network can do.

A SOME/IP map is therefore a good early picture of an Ethernet ECU: what it offers, to whom, and whether anything answers that should not.

How AutoST tests it

AutoST discovers SOME/IP services both passively, by listening to Service Discovery, and actively, with FindService. It maps services, methods and eventgroups to their endpoints, scores the exposure and feeds the result into the shared Fix Plan alongside the UDS, DoIP and IVI findings. It works at the service and network level and does not attack application logic behind a method, which is penetration-test work.

Common misunderstandings

SOME/IP is middleware, not a security layer, so an offered service is not a protected one. A reachable method is not automatically a vulnerability, but a method reachable by nodes that should never call it is worth a finding. And mapping services on the bench is discovery, not exploitation.

FAQ

Frequently asked questions

Does SOME/IP encrypt or authenticate its messages?

The core protocol does neither. Protection is layered around it: SecOC for message authentication, TLS or DTLS for transport, and VLAN separation and firewall rules in switches and gateways. Which of these a design uses is an OEM decision, not a protocol default.

What does SOME/IP-SD do?

Service Discovery runs on top of SOME/IP with service ID 0xFFFF and method ID 0x8100, usually over UDP multicast. Its entries include OfferService, FindService and SubscribeEventgroup, through which a receiver learns which service instances exist and on which address and port they answer.

How does SOME/IP differ from DoIP?

Both use automotive Ethernet but for different purposes. DoIP carries UDS diagnostics between a tester and ECUs. SOME/IP carries functional communication between ECUs, for example infotainment, camera or driver-assistance services, during normal operation.

Sources

Related pages

See it on your ECU

A term that matters for your ECU?

In 15 minutes we tell you how AutoST tests it, what a finding looks like and what it means for your ISO/SAE 21434 evidence.

  • Direct answer from an ECU security engineer
  • Which test covers the term
  • Free and without obligation
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk the AutoST team

Pick a time that suits you

Open in a new tab