Automotive Cybersecurity: Securing the Software-Defined Vehicle

By Mr. Subir Sangal, CEO, Eagle Information Systems

0
148

Modern vehicles are no longer mechanical machines alone. They have become vehicles defined by software with the help of electronic control units (ECUs) and software-defined services. Such features like remote access, navigation, assistance, and over-the-air updates are transforming modern cars into software-defined vehicles and adding smart and connected capabilities to vehicles.

At the same time, each new connection provides a new opportunity for hackers to attack the system. They could gain access not only to vehicle data and processes, but also to customer information, fleet management systems, and even compromise safety.

The Automotive Attack Surface Is Expanding

Within the connected vehicle, there are different systems that work together and interact with other networks as well. There are more possible points to attack within such a system.

The first type of attack may include hacking of digital keys and key fobs in order to get access to the car. The second possible way is using vulnerabilities in infotainment or telematics systems for further penetration into the vehicle’s network, such as CAN, which makes communication between different ECUs possible.

The usage of cameras, sensors, and other devices increases the number of vulnerabilities, since those collect and exchange information. Any attack on commercial vehicles or fleets might result in problems with their operation or logistics.

So, the issue is not just about protecting the vehicle but the whole connected vehicle environment as well.

Third-Party Software Can Create Hidden Risks

Nowadays, many manufacturers of cars use tier-1 and tier-2 suppliers and software vendors. As a result, a significant number of different suppliers may participate in the manufacturing process of each single car.

Such issues as supply chain security appear because the vulnerability of third-party software, media system, or ECU firmware may affect the security of several car models. For this reason, the manufacturer needs to identify all software and components used in his car and conduct proper testing of this product.

This may be done with the help of ISO/SAE 21434 automotive cybersecurity engineering. However, security isn’t only about automakers; suppliers need to present proper security measures as well.

Over The Air (OTA) Updates Are Becoming a Cybersecurity Battlefield

OTA technology makes it possible for auto makers to deliver updates and security fixes remotely via communications technology. It increases the ability to remedy any vulnerabilities after the car is released into the market.

But this update becomes a security threat in its own right. An attack on the OTA server or interception of the update package through the network can result in the spread of malware in the car’s network.

OTA technology will need stringent security measures in place in order to address such threats. These include code signing, encryption, authentication, and software verification. UN Regulation R156 provides these software update management specifications.

Who Protects the Data Generated by Connected Cars?

Connected vehicles generate massive amounts of data which include vehicle locations, driving patterns, vehicle operations, and even data collected via cameras and sensors. Connected data will, of course, increase rapidly and the question that follows this natural progression is, “Who will secure it?”

Connected data security is the responsibility of automakers, fleet operators, IT suppliers, insurers, and any other company or entity that handles vehicle data. Compromise in any part of this process could lead to exposure of critical personal and operational information.

The first instance that comes to mind involves telematic data collected by insurance companies to determine drivers’ driving patterns. Such data can easily be breached or tampered with.

Security Must Follow the Vehicle Throughout Its Life

However, when considering the issue of cybersecurity in relation to automobiles, the matter should not be approached by way of a final test after the manufacture of the car is completed. On the contrary, cybersecurity in relation to the automobile should be considered throughout the whole process of car manufacture and use.

As the trend of software-defined cars continues, there will always be a need for cybersecurity in such an industry. Every part of the manufacturing process will have to observe stringent cybersecurity practices.

Future development of intelligent transportation systems will rely not only on the intelligence that cars of tomorrow will have but also on their safety while operating. The security of software and systems in cars is the security of those who operate them.

By Mr. Subir Sangal, CEO, Eagle Information Systems

LEAVE A REPLY

Please enter your comment!
Please enter your name here