Post-EOL Cybersecurity Validation for Automotive Production ECUs

2026-26-0608

To be published on 01/16/2026

Authors Abstract
Content
ISO/SAE 21434 emphasizes comprehensive cybersecurity risk management throughout the automotive lifecycle. However, specific guidance on validating cybersecurity measures at the production level remains limited. This paper addresses the gap in production-stage validation, particularly after End-of-Line (EOL) flashing, which includes configurations of security hardware and software protection (e.g., UCB confirmation, JTAG, and P-flash password settings). Problem articulation: Current automotive cybersecurity validation methods, despite adherence to ISO/SAE 21434, lack specific procedures for the production stage. The existing system-level validation using the ASPICE V-model (e.g., SWE.6, SYS.5) does not ensure the integrity and functionality of cybersecurity features in the final manufactured unit post-EOL flashing. This gap poses a risk of vulnerabilities being introduced during the EOL process, compromising critical security measures. Proposed solution: To mitigate the cybersecurity risks in production units, particularly the binary which has been introduced during End-of-Life (EOL) flashing, we propose a dedicated testing phase on the right side of the V-cycle. This phase of testing will be focused on identifying and resolving vulnerabilities stemming from EOL flashing processes, such as incorrect memory addresses or erroneous configuration values to activate the cybersecurity protection. Value proportion: The current ASPICE V-cycle process lacks dedicated validation for software flashed via EOL procedures. This proposal addresses this critical gap by advocating for dedicated testing that will verify the integrity of hardware & Software Cybersecurity configuration (example: UCB addresses, values, JTAG passwords etc,). By implementing this validation process, we aim to substantially strengthen the overall cybersecurity solutions in production units. Stage of the paper: We have defined the necessary verification criteria and test cases and developed a performance testing strategy for the production unit testing stage. This strategy aims to ensure the robustness and reliability of cybersecurity measures in the final production units.
Meta TagsDetails
Citation
Chakraborty, S., Kulanthaisamy, N., and Sankar, G., "Post-EOL Cybersecurity Validation for Automotive Production ECUs," SAE Technical Paper 2026-26-0608, 2026, .
Additional Details
Publisher
Published
To be published on Jan 16, 2026
Product Code
2026-26-0608
Content Type
Technical Paper
Language
English