Approaches for bypassing/interfacing with OEM Security Gateways (SGW & VAG SFD2) for telemetry
Hello everyone,
I'm researching workflows to interface with modern automotive security architectures, specifically generic SGWs and VAG's SFD2 (UNECE R155/R156 compliance).
My main focus is streaming live diagnostic telemetry (UDS $22) and analyzing bus traffic without getting blocked by the gateway. I'd like to ask the community:
Downstream Physical Taps: Are you relying primarily on direct harness tapping downstream of the Central Gateway (e.g., tapping directly into Powertrain/Body CAN-FD) to bypass the SGW filtering entirely?
SFD2 Cryptographic State: Given that SFD2 moves beyond standard challenge-response into continuous online token validation/signatures, has anyone mapped out the offline attack surface, or is an authenticated OEM server backend strictly mandatory?
Tooling & Setup: What hardware setups (J2534 passthrough, custom CAN-FD sniffers, or gateway emulators) are you finding most effective for logging traffic during authenticated sessions?
Any teardowns, repo links, or research papers on SFD2 internals would be greatly appreciated.