u/Soggy-Ad-32

Approaches for bypassing/interfacing with OEM Security Gateways (SGW & VAG SFD2) for telemetry

Hello everyone,

I'm researching workflows to interface with modern automotive security architectures, specifically generic SGWs and VAG's SFD2 (UNECE R155/R156 compliance).

My main focus is streaming live diagnostic telemetry (UDS ⁠$22⁠) and analyzing bus traffic without getting blocked by the gateway. I'd like to ask the community:

Downstream Physical Taps: Are you relying primarily on direct harness tapping downstream of the Central Gateway (e.g., tapping directly into Powertrain/Body CAN-FD) to bypass the SGW filtering entirely?

SFD2 Cryptographic State: Given that SFD2 moves beyond standard challenge-response into continuous online token validation/signatures, has anyone mapped out the offline attack surface, or is an authenticated OEM server backend strictly mandatory?

Tooling & Setup: What hardware setups (J2534 passthrough, custom CAN-FD sniffers, or gateway emulators) are you finding most effective for logging traffic during authenticated sessions?

Any teardowns, repo links, or research papers on SFD2 internals would be greatly appreciated.

reddit.com
u/Soggy-Ad-32 — 4 days ago