SOME/IP (Scalable service-Oriented MiddlewarE over IP)
SOME/IP is the AUTOSAR middleware for services on automotive Ethernet: header, methods, events and service discovery. What it is and why exposed services are a finding.
Updated This page as Markdown
In short
SOME/IP (Scalable service-Oriented MiddlewarE over IP) is the AUTOSAR protocol with which ECUs on automotive Ethernet offer and call services: methods with request and response, events and fields. A 16-byte header carries the service and method IDs, a length, client and session IDs and a message type. SOME/IP Service Discovery announces which service instances run where. The protocol provides no authentication of its own, so a node on the network can discover and invoke whatever is offered.
What is SOME/IP?
SOME/IP is a remote procedure call and event protocol for ECUs connected by Ethernet. Each message begins with a 16-byte header: a message ID made of a 16-bit service ID and a 16-bit method ID (method IDs with the top bit set denote events), a 32-bit length that covers the rest of the header plus the payload, a request ID made of a client ID and a session ID, the protocol version 0x01, an interface version, a message type and a return code.
A request to service 0x1234, method 0x0001, with no payload is 12 34 00 01 00 00 00 08 00 01 00 01 01 01 00 00: length 8, client 0x0001, session 0x0001, protocol version 1, interface version 1, message type 00 (REQUEST), return code 00. A normal reply uses message type 0x80; an error reply uses 0x81, and return codes such as 0x02 (unknown service) and 0x03 (unknown method) reveal to a receiver what does and does not exist.
Where is it defined?
AUTOSAR specifies SOME/IP in its Foundation standard, in the SOME/IP protocol specification and the SOME/IP Service Discovery protocol specification, and it is implemented in both the Classic and the Adaptive Platform. There is no ISO standard for it. The threats that bear on it, spoofed messages and unauthorised access to functions, are among those listed for in-vehicle communication in UN R155 Annex 5.
What it means in practice
Because Service Discovery announces offered services to the network, the set of services an ECU exposes is visible to anything that listens. On infotainment and driver-assistance networks the recurring issues are services offered to the whole segment when a single client needs them, methods that run without checking who called, and subscriptions accepted from any address. Each of these widens what a node already on the network can do.
A SOME/IP map is therefore a good early picture of an Ethernet ECU: what it offers, to whom, and whether anything answers that should not.
How AutoST tests it
AutoST discovers SOME/IP services both passively, by listening to Service Discovery, and actively, with FindService. It maps services, methods and eventgroups to their endpoints, scores the exposure and feeds the result into the shared Fix Plan alongside the UDS, DoIP and IVI findings. It works at the service and network level and does not attack application logic behind a method, which is penetration-test work.
Common misunderstandings
SOME/IP is middleware, not a security layer, so an offered service is not a protected one. A reachable method is not automatically a vulnerability, but a method reachable by nodes that should never call it is worth a finding. And mapping services on the bench is discovery, not exploitation.
FAQ
Frequently asked questions
Does SOME/IP encrypt or authenticate its messages?
The core protocol does neither. Protection is layered around it: SecOC for message authentication, TLS or DTLS for transport, and VLAN separation and firewall rules in switches and gateways. Which of these a design uses is an OEM decision, not a protocol default.
What does SOME/IP-SD do?
Service Discovery runs on top of SOME/IP with service ID 0xFFFF and method ID 0x8100, usually over UDP multicast. Its entries include OfferService, FindService and SubscribeEventgroup, through which a receiver learns which service instances exist and on which address and port they answer.
How does SOME/IP differ from DoIP?
Both use automotive Ethernet but for different purposes. DoIP carries UDS diagnostics between a tester and ECUs. SOME/IP carries functional communication between ECUs, for example infotainment, camera or driver-assistance services, during normal operation.
Sources
Related pages
- GlossaryDoIP (Diagnostics over Internet Protocol)DoIP (ISO 13400) carries UDS over Ethernet: vehicle discovery, routing activation and diagnostic messages on port 13400. How it works and where gateways go wrong.
- GlossarySecOC (Secure Onboard Communication)SecOC is the AUTOSAR mechanism that authenticates in-vehicle messages with a MAC and a freshness value. How it works on CAN and what a bus test can check.
- GlossaryIVI (In-Vehicle Infotainment)IVI is the vehicle head unit that runs apps, media and connectivity, often on Android or Linux. Why it is a large attack surface and what hardening checks look for.
- InsightsSOME/IP security testing: what to check and whyHow to test SOME/IP on the bench: build a service inventory from service discovery, compare it to the matrix, check who can reach each service, and read results.
- PlatformFollow the ECU onto the network.AutoST tests automotive Ethernet: UDS over IP, DoIP routing activation and vehicle discovery, and SOME/IP service discovery with service and method mapping.
