Browse Topic: Cybersecurity

Items (629)
With the development of domestic vessel traffic service (VTS) systems, China has established a comprehensive maritime traffic management infrastructure. Marine sensing equipment, including radar, the automatic identification system (AIS), and electro-optical (EO) systems, provides diverse sources of ship information. In recent years, data fusion technology has attracted increasing attention for its potential to improve the accuracy and completeness of ship perception. This paper introduces key ship information sensing technologies and examines the distinct characteristics of each approach. It then reviews recent advances in three main areas: vision-based ship feature recognition, multi-source data association analysis, and ship motion prediction. Finally, the paper outlines prospective research directions, including the integration of additional data sources, real-time data processing, enhanced data security, and intelligent maritime decision-making.
Zhao, KuiSong, ZhemingHuang, Yuantao
Ultrasonic sensors are widely deployed in automotive driver assistance systems for near-range environment perception and provide safety-relevant inputs for functions such as parking assistance and automated parking. With increasing vehicle automation, the integrity and availability of ultrasonic sensor data become more critical, as compromised measurements may lead to incorrect vehicle decisions and hazardous behavior. While prior research has extensively studied physical attacks on ultrasonic sensors, a structured cybersecurity risk analysis in accordance with automotive cybersecurity standards, combined with experimental validation, is largely missing. In particular, the communication interface between ultrasonic sensors and control units has received limited attention despite its relevance as a potential attack surface. This paper presents a systematic security analysis of an automotive ultrasonic sensing system based on a demonstrator setup. The work applies a Threat Analysis and Risk Assessment methodology aligned with ISO/SAE 21434 and HEAVENS 2.0 to identify security-relevant assets, threat scenarios, and attack paths. Risk levels are derived by evaluating potential impact and attack feasibility. To validate the risk assessment, a structured test strategy is developed using the ISTQB test process and translated into laboratory experiments. Both digital attacks targeting the sensor communication interface, with DSI3 selected as the representative protocol, and physical manipulations of the sensor environment are examined. Experimental results show that selected communication-level attacks can be realized with moderate effort and can cause controlled falsification or loss of measurement data. Physical environmental manipulations significantly degrade signal quality but do not fully suppress object detection in the evaluated configuration. The findings largely confirm the initial risk assessment while enabling refinement of attack feasibility parameters. The results provide a validated linkage between automotive cyber-security risk assessment methods and practical testing of ultrasonic sensing systems and underline the importance of jointly addressing communication interfaces and physical effects in future security concept development.
Gahm, SebastianHaller, JonathanKriesten, Reiner
This report provides a survey of side channel and fault injection attacks that have an impact on automotive embedded systems. The focus is on side channel attacks that target cryptographic algorithms and hardware security engines, as well as sensitive data leakage. The report also considers fault injection attacks against typical vehicle components that allow bypassing of security controls to compromise the target system security and outlines some countermeasures to detect and/or prevent them. The report provides a list of security countermeasures that can be considered by manufacturers based on their risk tolerance to such attacks. Additionally, it offers the automotive industry supply chain a common language to facilitate the communication of side channel and fault injection mitigation requirements among the various stakeholders.
Vehicle Electrical System Security Committee
1Systems level and integration testing are an integral part of the design and development of Automated Vehicles (AVs). Measurement science plays a pivotal role in testing to ensure the safe and efficient operation of AVs. This science establishes a common understanding of the units of measurement, crucial in linking human activities. This article describes the significance of measurement in studying interactions between key system technologies in AVs, including AI for perception, sensing, communications, and cybersecurity. To address the complexities of these interactions, a novel, adaptable, and interactive framework called the System Technology Interaction Model (STIM) is introduced. STIM considers both designed and emergent interactions between these system technologies, allowing AV developers to explore tailored experiments with the flexibility of filtering for focused testing. The framework currently models system interactions statically, not in real-time, to define potential relationships and influences during the design phase. The novelty of this framework comes from providing a holistic evaluation that captures testing of interactions between modules in addition to component-level testing, while other frameworks focus on testing individual component behaviors. It also assesses the equality of two interactions, meaning it ensures that two interactions behave the same way for consistent results. Moreover, the framework serves as a valuable tool for AV designers and safety regulators to aid in establishing robust design and assessment approaches. This work highlights the need for a common framework to thoroughly test AVs and gain a holistic understanding of system interactions. Finally, the framework aims to understand how to mitigate potential influences leading to AV malfunctions to advance the development and deployment of safe and reliable Automated Vehicles. The work focuses on level 1 and level 4 automated driving features to simplify the work, although it can be from level 1 to level 5. Although framework performance is inherently difficult to quantify, this framework’s performance can be reflected through its ability to accurately capture system interactions for improved AV design and support a broader usability among AV stakeholders. In the future, the framework can be expanded to include additional elements, such as infrastructure or other vehicles, to analyze information provided to AVs, allowing experts from various domains to collaborate, create similar models, integrate them when feasible, and model the interactions in real-time.
Griffor, Edward R.Arora, MahimaKootbally, ZeidNguyen, Vinh
Automotive Engineering: June 202626AUTP066/4/2026
New York 2026: diversity on full display New powertrain choices keep popping up on new vehicles from OEMs that debuted at NYIAS this year. Sealing integrity in a Formula 1 limited-slip differential High-temperature hydraulic control in a Formula 1 drivetrain requires dimensional stability, controlled sealing force, and resistance to wear under sustained pressure cycling. Inside the limited-slip differential, the sealing architecture plays a defined mechanical role in maintaining consistent torque management under race conditions. From ADAS to autonomy How engineering thermoplastics can advance sensor-based technologies. Synthetic data and the future of ADAS validation Why ADAS validation can't be solved with more miles alone. Intelligent power distribution will change the way vehicles are designed Electronic fuse (eFuse) technology can create electronic power distribution modules (ePDMs) for architectural flexibility, higher reliability, greater safety, and proactive maintenance. Editorial Maybe more than ever, let's talk transportation diversity The Navigator Can legacy automakers finally succeed with SDVs? AI scares and excites cybersecurity professionals at WCX Expert claims war hurting China's already-struggling economy NHTSA open to negotiated rulemaking on some safety issues Resilient propulsion strategies require options Driven: Honda Fastport eQuad Prototype Product Briefs Spotlight: Connectors & harnesses, EV thermal management Q&A Neural Concept's Thomas von Tschammer: Working with AI at speed
It's not difficult to find warnings about the dangers of AI. The news that Anthropic's new AI tool is too dangerous for the public due to its alleged hacking capabilities should be of concern to every company making software. That includes automakers. Software has been part of the vehicles in our driveways for decades. In the past few years, even more so, with the push for software-defined vehicles (SDV). At SAE's 2026 WCX conference, a group of cybersecurity professionals from the vehicle industry discussed what AI and SDVs mean for current and future vehicles and how their jobs are about to get simultaneously easier and more difficult.
Baldwin, Roberto
Modern avionics programs contend with escalating complexity driven by concurrent safety certification, cybersecurity compliance, and multi-standard regulatory demands. Traditional program management approaches treat risk management as a parallel support function rather than a central governance mechanism, resulting in reactive responses that fail to prevent cost and schedule erosion. This paper introduces the Risk-Driven Program Management Framework (RD-PMF), an eight-phase governance model that embeds quantitative risk assessment, standards-risk mapping across DO-178C, DO-326A, ARP4754A, and ARP4761A, real-time digital dashboards, and earned value management within core program decision-making. The framework integrates probabilistic schedule analysis using Monte Carlo simulation with continuous risk exposure monitoring to enable proactive, data-driven governance. RD-PMF is demonstrated through a representative avionics program scenario modelled on a flight control system development effort with a 24-month baseline schedule, $15 million budget, and 27 identified risks. Simulation parameters, informed by the authors’ professional experience in avionics program management and published industry benchmarks, illustrate framework applicability within industry-typical ranges. Five targeted risk mitigation strategies, with a combined investment of $1.27 million addressing certification review delays, requirements volatility, supplier delays, hardware-software integration, and cybersecurity threats, reduced aggregate risk exposure by 77 percent (64.7 to 15.1 schedule-weeks). The demonstration yields an 11 percent schedule performance index improvement (SPI: 0.88 to 0.98), a 6.5 percent cost performance index improvement (CPI: 0.92 to 0.98), schedule variance reduction from 8.0 to 1.2 weeks, and a 2.5-month acceleration in projected completion. Return on investment analysis shows 2.22x gross (1.22x net) on mitigation spending, with total quantified benefits of $2.82 million. These results illustrate a measurable shift from reactive program control to proactive, risk-informed governance suited to next-generation aerospace development programs.
Rahul, SaurabhBenikireddy, Raghunatha
Automatic Dependent Surveillance–Broadcast (ADS-B) has become a cornerstone of modern aviation, revolutionizing Air Traffic Management (ATM) through its ability to continuously transmit real-time flight data—including GPS-derived position, altitude, and velocity. Since its widespread operational deployment over the past decade, ADS-B has significantly enhanced situational awareness, improved safety, extended surveillance coverage into previously unmonitored airspace, and enabled more efficient aircraft routing and separation. However, despite its many advantages, the fundamental design of ADS-B introduces notable security vulnerabilities. Because ADS-B signals are unencrypted and unauthenticated, malicious actors can inject fraudulent broadcasts, creating the illusion of non-existent aircraft. Such spoofing attacks can trigger false cockpit alerts and distract pilots during critical phases of flight. The current ADS-B data format prioritizes simplicity to accommodate a broad range of users, including Air Traffic Control (ATC), ground stations, flight crews, and aviation tracking services. Yet, as ADS-B IN becomes increasingly integral to tactical decision-making, the need for robust security mechanisms grows more urgent to safeguard flight operations. This paper highlights the imperative for a balanced approach to ADS-B security, one that strengthens protection for essential flight functions while preserving open access for non-sensitive applications. It argues that while enhanced security is vital for operational integrity, overly restrictive protocols should not hinder the broader utility of ADS-B data. Ensuring that all stakeholders can continue to benefit from this critical technology without compromising safety is key to its sustained effectiveness.
Chikkegowda, KanthaShetty, RameshKhan, KalimullaSahoo, Subhransu
In recent years, the use of software-defined platforms has become increasingly prevalent. As a result, flashing ECUs has become an important factor in ensuring efficiency, quality, and compliance in vehicle production. Conventional approaches, such as final end-of-line flashing, are increasingly unsuitable for the growing amounts of data, complex dependencies, mixed physics and protocols, and traceability requirements. This SAE paper presents the current trends and challenges in ECU flashing. It highlights the impact of the exponential growth in software payloads and the necessary migration to offline and parallel workflows. This can only be achieved through closer integration with automated and robot-assisted production, considering the requirements of cybersecurity and verifiability. It also addresses the shift toward end-to-end flashing ecosystems, where updates are performed consistently from a single source covering the assembly line, warehouses, yards, workshops, and over-the-air updates. By comparing old and new approaches to high-speed flashing and presenting a new flashing strategy for OEMs derived from this, the paper provides a framework for understanding the future of ECU flashing on its way to software-defined mobility.
Böhlen, BorisBudak, OguzWells, Michael
The objective of this paper is to understand the effort required to integrate the hardware and software of in-vehicle cybersecurity systems. The in-vehicle cybersecurity method discussed is the SAE J1939-91C, which involves Network formation, Rekeying, and secure Message Exchange between Electronic Control Units (ECUs). The SAE J1939-91C network security protocol operates over a CAN-FD network to perform necessary cryptographic operations and key generation. To evaluate the method, test vectors were created to validate SAE J1939-91C key generations and cryptographic operations on the simulated ECU in-vehicle network system hardware (such as the Beacon or Pi devices). We introduce a lightweight, transport-agnostic benchmark comprising deterministic AES-CMAC test vectors and a simple verification utility, requiring no specialized hardware or build system. This minimal artifact set enables reproducible and machine-parsable validation of SAE J1939-91C security across diverse lab environments.
Zachos, MarkMedam, Krishna Teja
The useability of development processes in the automotive sector has decreased in the past years to a level at which their application and true benefit to is being questioned. Such degradation can be attributed to new additions to the processes and introduction of FuSa and Cybersecurity standards. The processes try to keep up with the shift from the traditional ‘plan–implement–test–roll-out' methodology to more agile methods. In addition, process departments typically in charge of these processes, focus on compliance to the letter of the standard to achieve certification, often with little thought to the actual implementation and the process they will be used by their engineering teams. Process growth to meet the needs of new and more complex technologies often mandates the use of new tools, which if implemented incorrectly can lead to unnecessary bureaucracy and additional overheads. Furthermore, the language of these new processes is in a form from assessor, making it difficult for an engineer to understand, interpret and implement. As a result, engineers become annoyed, losing productivity and motivation when working with what they perceive as burdensome standards, that simply exist to slow development. This has a huge impact on the competitiveness of companies especially in markets that are facing existential threats from internal and external pressures such as the automotive industry. Against popular belief, the application of generative AI (and large language models) will not solve the problem. On the contrary, it risks automating complex processes in the same unfamiliar language and creating documents to serve process overhead, rather than engineering development. This paper presents inefficiencies in the current state-of-the art processes used in the automotive sector and proposes a structured approach that increases the efficiency of automotive software development. It does so by documenting and implementing development processes based on how engineers actually perform their work. In the second step the adjustments that are necessary to ensure compliance of the product with industry standards are made. Such an approach produces efficient, compact and compliant process definition.
Weber, MatthiasKmiec, MateuszRomijn, MarcelNedkov, Detelin
Electric vehicles (EVs) rely extensively on sensor feedback for safe and efficient powertrain operation. However, this dependency introduces cyber-physical vulnerabilities, especially when sensor signals are maliciously manipulated. This paper presents a simulation-based investigation into sensor-level cyberattacks on a mid-sized EV powertrain model developed in MATLAB/Simulink. The study quantifies mechanical consequences and evaluates mitigation strategies to enhance system resilience. Four representative attack scenarios were simulated. Speed sensor spoofing led the controller to misinterpret vehicle velocity, causing a 41% overshoot beyond the 50 km/h setpoint. False data injection into torque/current sensors triggered an unintended torque surge of approximately 20%, resulting in inverter current saturation within 2 seconds. Battery temperature spoofing delayed thermal protection, allowing a deviation of 1.5 °C/min beyond safe operating limits. A hybrid attack combining frozen speed feedback with a forced 100% throttle input caused runaway acceleration and actuator saturation lasting over 10 seconds. These scenarios demonstrate how localized sensor attacks can propagate through control loops, destabilizing vehicle dynamics. To counter these threats, we implemented signal plausibility checks, observer-based anomaly detection, and fail-safe torque limiting. These measures collectively reduced overshoot by more than 50% in spoofing cases. Beyond simulation, we propose a multi-layered defense framework incorporating cross-sensor validation, statistical and machine learning-based anomaly detection, guided by ISO/SAE 21434 cybersecurity engineering principles, signal-level defenses, and conservative fallback controls. By linking cyber intrusions to tangible mechanical instabilities and validating countermeasures through simulation, this work offers actionable insights for engineers developing robust and secure EV powertrains. It underscores the necessity of integrating mgechanical and cybersecurity disciplines to ensure the safety and reliability of future electric mobility systems.
Tariq, UsamaSahandabadi, SaherehDianat, Ali
Negotiating Keys for applications such as message authentication within a vehicle presents many problems as, in designing the algorithm; the algorithm must be able to be utilized by small, fixed-point processors. In addition, if there is a desire to do this algorithm in the manufacturing environment, there are severe time constraints placed on how long this algorithm can take, as there are strict station time requirements, which are expensive to change, and any time utilized in the plant can negatively affect vehicle throughput. Additionally, negotiating these keys between many ECUs can greatly increase the time required to negotiate a common key using standard multi-party Diffie-Hellman. Timing would also be an issue in the case of using pair-wise Diffie-Hellman for encryption and distribution of keys utilizing a key master. To solve these problems in multi-party key negotiation, we have utilized the Elliptic Curve variation of the Burmester-Desmedt (ECBD) algorithm. ECBD is relatively fast for a large number of ECUs, though the primary benefit of utilizing this algorithm is that calculation times for key negotiation vary only slightly for a wide range of number of participants. This enables the easy planning of negotiation time based on the number of keys the vehicle requires without worrying about the number of ECUs that require each key. This approach also has advantages over key injection and direct key distribution schemes because it does not require a secure environment at any point in the process. Thus, ECBD can be implemented without a secure clean room in either the manufacturing or maintenance environments. This is especially valuable in the maintenance environment, as it enables easy compliance with right to repair laws without endangering vehicle cyber security.
Van Dam, TheoMazzara, Bill
The evolution toward software-defined vehicles (SDVs) is causing disruption to the traditional automotive supply chain and breaking down the common hierarchical OEM, tier 1 supplier, and tier 2 supplier relationships. With demands for faster software release cycles, more advanced software projects involving multi-party development, and considerations for end-to-end embedded and cloud integrations, new cybersecurity challenges are introduced that no single organization can address alone. Thus, this disruption creates new trust dependencies and requires new models for collaboration, transparency, and joint responsibility in cybersecurity. This paper presents a collaborative cybersecurity model, emphasizing shared responsibility during multi-party development between OEMs, tier 1 and 2 suppliers, engineering services organizations, and technology and services providers. As such, we explore collaborative approaches for each stage in the development lifecycle including design, development, testing and validation, and post-release activities. This includes joint development frameworks, standardized communication and reporting approaches, and cooperative continuous cybersecurity activities. These collaborative approaches enable the involved parties to maintain trust, mitigate cross-organization risks, and support rapid innovation while assuring cybersecurity. The current traditional siloed approaches or purely internal monitoring practices cannot adequately address new multi-party risks. Thus, as the automotive supply chain is disrupted, cybersecurity must also be considered in a collaborative manner in order to secure vehicles throughout the development lifecycle across a distributed and rapidly changing supply chain. Therefore, our paper focuses on a collaborative model that provides a practical, pre-competitive framework that allows to tackle cybersecurity cooperatively while enabling agile software delivery.
Oka, Dennis KengoVinzenz, Nico
The emergence of AI-driven autonomy in modern vehicles marks a pivotal evolution in transportation, but it also introduces deep system-level vulnerabilities that span from sensor interface tampering to compute unit compromise and untrusted communication links. Autonomous vehicles (AVs) operate as distributed intelligent systems, relying on real-time data exchange between zonal gateways, AI compute platforms, and safety-critical electronic control units (ECUs). These interactions must be protected from hardware-based attacks that could compromise functional safety, system integrity, or operational availability. The deployment of AI-driven AVs introduces unprecedented levels of complexity. Sensors, AI compute clusters, and actuators communicate over multiple interfaces including Ethernet, PCIe, and MIPI, exposing vehicles to potential cybersecurity attacks. This paper proposes a unified, layered hardware security architecture tailored for AI-powered automated vehicles. Grounded in current automotive Ethernet and zonal architectures, it provides end-to-end trust using hardware interface security, accelerated- cryptography, and SRAM PUF-based key provisioning. All security primitives are anchored to hardware root of trust, delivering cryptographic identity, secure boot enforcement, and trusted key storage across the entire vehicle lifecycle.
C Suriyanarayanan, PavIacob, Radu
Vision-language models (VLMs) are increasingly used in autonomous driving because they combine visual perception with language-based reasoning, supporting more interpretable decision-making, yet their robustness to physical adversarial attacks, especially whether such attacks transfer across different VLM architectures, is not well understood and poses a practical risk when attackers do not know which model a vehicle uses. We address this gap with a systematic cross-architecture study of adversarial transferability in VLM-based driving, evaluating three representative architectures (Dolphins, OmniDrive, and LeapVAD) using physically realizable patches placed on roadside infrastructure in both crosswalk and highway scenarios. Our transfer-matrix evaluation shows high cross-architecture effectiveness, with transfer rates of 73–91% (mean TR = 0.815 for crosswalk and 0.833 for highway) and sustained frame-level manipulation over 64.7–79.4% of the critical decision window even when patches are not optimized for the target model. We further find asymmetric architecture-level risk, with Dolphins most vulnerable to incoming transfer attacks (VS = 0.82) and LeapVAD producing the most transferable patches (TO = 0.882), while models sharing CLIP-based vision encoders exhibit stronger bidirectional transfer. Overall, these results indicate that current VLM-based autonomous driving systems share systematic cross-architecture weaknesses that architectural diversity alone does not resolve, underscoring the need for defenses and design principles that explicitly account for transferability in safety-critical deployment.
Fernandez, DavidMohajerAnsari, PedramSalarpour, AmirPese, Mert D.
Automated Driving Systems (ADS) rely on AI algorithms, machine learning, and sensor fusion to perform autonomous driving tasks. Safety challenges arise due to the probabilistic behavior of AI/ML algorithms and the need to ensure safety within defined Operational Design Domains (ODDs). Traditional standards such as ISO 26262[3] (Functional Safety) and ISO 21448[4] (SOTIF) address hardware and software failures or functional deficiencies but are insufficient for higher-level autonomous systems (SAE Levels 3–5). To close this gap, additional standards such as UL 4600[1] and ISO 5083[2] provide complementary frameworks for ADS safety assurance. UL 4600[1] establishes a claim-based safety case encompassing the vehicle, infrastructure, and processes, emphasizing structured arguments supported by evidence and reasoning. It offers guidance on autonomy functions, V & V, tool qualification, dependability, and safety culture. ISO 5083[2] focuses on design, verification, and validation of ADS, extending safety lifecycles with system-level principles, risk criteria, and validation metrics. It defines the ADS safety case as proof of acceptable safety for specific features and environments, stressing safety-by-design, layered verification, and post-deployment monitoring, including cybersecurity. Together, UL 4600[1] and ISO 5083[2] enable a unified approach to safety assurance, aligning with Functional Safety and SOTIF principles. Their integration helps manufacturers evaluate ADS systematically, demonstrate risk acceptance, and maintain safety throughout the lifecycle.
Mudunuri, Venkateswara RajuAlmasri, HossamFan, Hsing-Hua
This paper presents a simplified approach to model thermal runaway propagation in a multi-cell battery pack, with the goal of designing a safe and lightweight pack for mass-sensitive applications. The key parameters which characterize single-cell thermal runaway, including heat release profile, apparent cell emissivity and mass loss, were extracted from empirical nail penetration tests. This characterization was used to drive a three-dimensional thermal model of a 19-cell hexagonal sub-pack with a center trigger cell. To enable rapid design exploration, a symmetry-based computationally simplified domain was used for a full-factorial Design of Experiments (DOE) varying cell spacing, epoxy thickness, heat spreader thickness, and cup geometry. The DOE results were used to identify dominant heat-transfer mechanisms, capture main and interaction effects, and determine mass-efficient design levers governing peak-neighbor cell temperature during propagation. Insights from the DOE study informed the design of a physical prototype and the placement of thermocouples for model validation. Measured temperature data showed good agreement with model predictions across multiple initiator locations, with 4–7 °C error in peak temperature and 3–5 s error in time to reach peak temperature. However, accurate reproduction of the observed trends required increasing epoxy thermal conductivity on the initiator cell to represent epoxy carbonization observed during post-test teardown. This simplified modeling approach, paired with targeted testing, can provide practical design guidance, reduce overall testing cost, and enable fast development of mass-optimized, propagation-resistant battery packs.
Kalyankar, ApoorvOwen, ElliotStrohmaier, KyleMardall, Joseph
The automotive industry is evolving from a reactive, independently self-determined approach to cybersecurity, complicated by a complex supply chain. Over time, this has resulted in a fragmented industry comprised of any number of proprietary solutions verses a standardized, regulated paradigm to facilitate a platform-oriented approach. This document, an update on collaborative work from the SAE Vehicle Electrical Hardware Security Task Force (TEVEES18B) and GlobalPlatform Automotive Task Force, outlines this transition strategy. An extensible number of additional examples of use cases of Global Platform Technologies are explored in this document.
Mazzara, BillRawlings, Craig
This document provides guidance to using Rust in critical and safety-related software. The document summarizes how the usage of Rust supports in arguing safety according to ISO 26262 or RTCA DO-178C combined with RTCA DO-332. Cybersecurity best practices are referenced as these requirements largely overlap with those implemented for safety. As the Rust language is still evolving, this document targets the 2021 and 2024 editions of the language. Older or newer editions might require additional or changed rules and guidelines. Generally, the newest available edition of the language should be selected as newer editions remove ambiguities and outdated parts from the language.
Functional Safety Committee
As the automotive industry transitions toward software-defined vehicles and highly connected ecosystems, cybersecurity is becoming a foundational design requirement. A challenge arises with the advent of quantum computing, which threatens the security of widely deployed cryptographic standards such as RSA and ECC. This paper addresses the need for quantum-resilient security architectures in the automotive domain by introducing a combined approach that leverages Post-Quantum Cryptography (PQC) and crypto-agility. Unlike conventional static cryptographic systems, our approach enables seamless integration and substitution of cryptographic algorithms as standards evolve. Central to this work is the role of Hardware Security Modules (HSMs), which provide secure, tamper-resistant environments for cryptographic operations within vehicles. We present how HSMs can evolve into crypto-agile, quantum-safe platforms capable of supporting both hybrid (RSA/ECC + PQC) and fully post-quantum deployments—ensuring secure transitions without requiring hardware replacement. The novelty of this work lies in the design and validation of a first-of-its-kind operational prototype that supports current cryptographic standards (RSA/ECC) and is engineered for plug-and-play migration to PQC. Our architecture ensures long-term security while minimizing operational disruption and costs. Using a systematic architectural methodology, we integrated both software- and hardware-based HSMs and evaluated their performance under hybrid cryptographic conditions. Key performance metrics such as latency, key negotiation time, and re-keying efficiency demonstrate that crypto agility can be achieved with minimal overhead, confirming its feasibility for real-world deployment. There is an urgent need to adopt quantum-safe and agile security practices today, as vehicles manufactured now will remain in service long after quantum computers become practical. By embracing crypto-agile designs, automakers can mitigate long-term risks and ensure resilience against future cryptographic threats. This paper provides both a technical roadmap and a working prototype demonstration to guide the automotive industry toward a secure, quantum-resilient future.
Kuntegowda, Jyothi
Software-defined vehicles are those whose functionalities and features are primarily governed by software, thus allowing continuous updates, upgrades, and the introduction of new capabilities throughout their lifecycle. This shift from hardware-centric to software-driven architectures is a major transformation that reshapes not only product development and operational strategies but also business models in the automotive industry. An SDV operating system provides the base platform to manage vehicle software and enable those advanced functionalities. Unlike traditional embedded or general-purpose operating systems, it is designed to meet the particular demands of modern automotive architectures. Reliability, safety, and security become crucial because even minor faults may have serious consequences. Key challenges to be handled by the SDV OS include how to handle software bugs, perform real-time processing, address functional safety and SOTIF compliance, adhere to regulations, minimize attack surface exposure, and protect against remote access and data breaches. This is achieved via sound architectural principles, including a CSM for fine-grained access control, a lean and minimal kernel to reduce vulnerabilities, secure and efficient inter-process communication, and user-level drivers to provide better fault isolation. The key novelty of this approach rests on the fact that it uses open-source kernels, libraries, and tools that guarantee flexibility, clarity, and community-driven innovation. It provides a flexible runtime environment and OS-level isolation using virtualization, safe hardware sharing, and adherence to safety standards to set up the SDV OS as a resounding, secure, and future-ready base for next-generation automotive systems.
Khan, Misbah UllahGupta, Vishal
Modern vehicles require sophisticated, secure communication systems to handle the growing complexity of automotive technology. As in-vehicle networks become more integrated with external wireless services, they face increasing cybersecurity vulnerabilities. This paper introduces a specialized Proxy based security architecture designed specifically for Internet Protocol (IP) based communication within vehicles. The framework utilizes proxy servers as security gatekeepers that mediate data exchanges between Electronic Control Units (ECUs) and outside networks. At its foundation, this architecture implements comprehensive traffic management capabilities including filtering, validation, and encryption to ensure only legitimate data traverses the vehicle's internal systems. By embedding proxies within the automotive middleware layer, the framework enables advanced protective measures such as intrusion detection systems, granular access controls, and protected over-the-air (OTA) update channels. This strategy enhances both data security and system isolation, creating protective boundaries between critical vehicle operations and potential external attacks. The architecture particularly excels in supporting Vehicle-to-Everything (V2X) connectivity, facilitating seamless information exchange between vehicles, roadside infrastructure, and pedestrians. This capability is essential for enhancing roadway safety, optimizing traffic flow, and supporting autonomous driving technologies. The system incorporates dedicated proxy modules for specialized protocols including Trivial File Transfer Protocol (TFTP), Diagnostic Over Internet Protocol (Doip), and Message Queuing Telemetry Transport (MQTT), each fulfilling specific functions in vehicle diagnostics, software updates, and telemetry data management. Performance evaluations will measure latency and throughput metrics to validate the architecture's efficiency and reliability. The framework's modular design aims to provide scalability and adaptability to accommodate both technological advancements and emerging security challenges. The proxy-based security framework presented offers a holistic and forward-looking approach to safeguarding in-vehicle networks. It provides automotive manufacturers with the tools to develop connected vehicles that combine intelligence and efficiency with robust protection against diverse cybersecurity threats.
M, ArvindPraneetha, Appana DurgaRemalli, Ravi Teja
As electric vehicles adoption becomes more common, power grid operators are facing new challenges in managing the unpredictable and varying energy demands in the existing electrical infrastructure. Moreover, the cost of Electric vehicle is high when compared to fuel vehicle it has limited access to charging infrastructure along with the driving range that act as a key barrier preventing the drivers from making shift to EVs. When the EV usage integrates with blockchain, it mitigates the limitation in charging station infrastructure along with the former problem discussed. The lack of trust exists between EV owners and charging station providers can be solved through secure and transparent payment processing possible by blockchain based smart contract. Building charging station on blockchain will ease the automated payment through the use of smart contract and create more efficient EV charging network. Also, the blockchain-based charging system would enable EV owners know if they are being charged in excess and Prosumer know if they are being underpaid. The high initial cost is another prominent issue within the market place. To address this issue the introduction of sharing economy to the EV industry showcases another innovative solution that blockchain offers. The blockchain enabled sharing economy platform allows individuals to access collaboratively with the prosumer and the consumer. This provides alternative to traditional ownership while reduces individual financial barriers and maximizing electric vehicle utilization across the network. The EV users have great opportunity worldwide to take a stake in the future of EV adoption on blockchain. Therefore, this work demonstrates the sharing economy while designing, building, and customizing smart contracts for prosumers and consumers by enabling decentralized payment systems. Our research aims to develop decentralized charging electronic payment systems using blockchain and customized smart contracts to build and design the application. For blockchain Solidity programming language is used. The application displays the charging process, payment system, and charging history information.
Govindasamy, DhivyaR, Rajarajeswari
Effective communication is the key for bringing harmony - be it the communication between humans and humans, or communication between machine and machine. Today’s car is a sophisticated gadget, equipped with the best of technologies running using millions of lines of codes of software. The effective use of these technologies involve communication between car to car and car to infrastructure using Dedicated Short-Range Communication (DSRC), C-V2X (Cellular Vehicle-to-Everything). It is pertinent that any communication using the internet needs to be digitally secure and that the systems are designed to mitigate the perceived threats. The methods used for ensuring cyber safety of automobiles need to be verified before the end product is put to use. Automotive Industry Standards AIS-189 and AIS-190 have been formulated to provide a harmonized verification framework. Both the vehicle manufacturer and the test agency need to equip themselves with necessary skills and tools to ensure compliance as per the laid down norms. With the ever-increasing use of software to run vehicles, the regulatory requirements would need to be constantly updated by reviewing the future threats involved and probable measures to mitigate them. The paper presents an overview of these important elements of cyber security regulations viz., applicable standards and approval procedure and means for a constant update of the two.
Nayak, PratikTandon, VikramBadusha, AkbarDesai, ManojSathianesan, Rejin
The rapid adoption of connected vehicle technologies and advanced driver assistance systems (ADAS) necessitates robust security mechanisms capable of identifying and mitigating sophisticated cyber threats in real-time. Traditional signature-based intrusion detection systems (IDS) are often inadequate in addressing the dynamic and evolving nature of automotive cybersecurity threats, particularly in modern vehicle networks like Controller Area Network (CAN), CAN with Flexible Data-Rate (CAN-FD), and Automotive Ethernet. This research introduces a novel Real-time Intrusion Detection System utilizing advanced Machine Learning (ML) techniques designed specifically for automotive network environments. The proposed IDS framework employs supervised and unsupervised ML algorithms, including anomaly detection, behavioral analytics, and predictive threat modeling, to achieve high accuracy and rapid threat identification capabilities. Through extensive testing in simulated and actual vehicle network scenarios, the developed IDS model demonstrates significant improvements over conventional detection methods, notably in precision, recall, detection latency, and adaptability to zero-day threats. This research further evaluates the proposed system’s alignment with critical regulatory standards such as AIS 189 and UNECE WP.29, ensuring its practical applicability within automotive industry cybersecurity compliance frameworks. The findings highlight the potential for ML-driven IDS solutions to substantially enhance automotive cybersecurity posture, providing OEMs and stakeholders with actionable insights for proactive threat management.
Chaudhary lng, VikashDesai, ManojChatterjee, Avik
The rapid expansion of electric vehicle (EV) charging infrastructure introduces complex cybersecurity challenges across hardware, software, network, and cloud layers. This review paper synthesizes existing research, standards, and documented incidents to identify critical vulnerabilities and propose layered mitigation strategies. We present a structured threat taxonomy based on the STRIDE model, enriched with real-world attack vectors and mapped to mitigation controls. Our analysis spans physical tampering, insecure firmware updates, protocol-level flaws in OCPP and ISO 15118, and cloud misconfigurations. While prior studies often focus on isolated domains, this work unifies fragmented insights into a cohesive framework. We highlight gaps in current literature, such as inconsistent adoption of secure protocols and limited validation of EVSE identity formats. By aligning threats with industry standards (SAE J3061, NIST CSF, IEC 62443) and scoring risks using CVSS v3.1, we offer a practical roadmap for manufacturers, operators, and policymakers. The paper concludes with recommendations for future research, including experimental validation, blockchain-based audit trails, and AI-driven anomaly detection.
Aggarwal, AkshitGupta, SaurabhSirohi, KapilArisetty, VenkateshChatterjee, Avik
Modern cars have advanced significantly with the rapid growth of connectivity and communication technologies. In the wake of rising cyber attacks and enforcement of regulations, implementation of cybersecurity is imperative to safeguard vehicles. The cybersecurity controls such as secure boot, secure updates, and secure communication require cryptographic primitives (keys/certificates). These security features are largely dependent on robust Key Management System (KMS), as keys are the sensitive assets that must be protected throughout the lifecycle of vehicle. Several security critical applications like over-the-air and car-to-car interaction essentially needs robust KMS to protect the vehicle assets from expanding attack vectors. Traditionally KMS is established centrally in a backend server. The cloud based KMS is becoming complex due to increased number of keys/certificates required to provision in a vehicle. We propose a self-governing in-vehicle key management system for a gateway-based architecture. The solution is derived from core principles of Blockchain technology. Every key or certificate transaction is recorded in a registry, with the first block (genesis block) created during the vehicle manufacturing stage by the gateway. The first stage involves creation of a genesis block, followed by the generation of a PKI blockchain for each ECU during vehicle manufacturing. In the second stage, the established PKI blockchain will be utilized for secure on-road communication during vehicle operations. Key management operations such as key rotation, revocation, addition, and replacement will be performed based on the established blockchain, with the gateway serving as the anchor point. Each key management operation is appended to the chain starting from the genesis block, with updates securely broadcast and replicated across all ECUs ensuring a distributed, tamper-proof key management framework. Several diverse communications like CAN, CAN-FD and Ethernet are comparatively analyzed, against its usage, benefits and complexity in the proposed approach.
Goyal, YogendraSutar, SwapnilJaisingh, Sanjay
Automotive Over-the-Air (OTA) software updating has become a cornerstone of the modern connected vehicle, enabling manufacturers to remotely deploy bug fixes, security patches, and new features. However, this convenience comes with significant cybersecurity challenges. This paper provides a detailed examination of automotive OTA update security and the software store (software Applications & services store) mechanisms. I discuss the current industry standards and regulations, notably ISO/SAE 21434 and the United Nations Economic Commission for Europe (UNECE) regulations UN R155 (cybersecurity) and UN R156 (software updates) and explain their relevance to secure OTA and software update management. I then explored the Uptane framework, an open and widely adopted architecture specifically designed to secure automotive OTA updates. Next, OTA-specific threat models are analyzed, detailing potential attack vectors and corresponding mitigation strategies. Real-world case studies are presented to illustrate both the risks and the successful deployment of secure OTA systems in the industry. I conclude with insights into best practices for implementing a robust, compliant OTA update ecosystem, emphasizing a global perspective on regulations and the need for continuous vigilance throughout the vehicle lifecycle.
Kurumbudel, Prashanth Ram
This paper explores the implementation of ISO 21434 Automotive Cybersecurity Assurance Levels (CAL), focusing on enhancing component level cybersecurity for a vehicle. CAL values, which range from 1 to 4, provide a metric for ensuring that assets are protected against relevant threats at various phases of the product life cycle. By identifying parameters in the attack feasibility rating and their severity early in the product life cycle, specifically during the concept phase of ISO 21434, organizations can determine the CAL values. The CAL value serves as a benchmark to determine the level of severity required during the design, development and verification phases of the product life cycle. This paper outlines a method to establish CAL values as per ISO 21434 guidelines. The proposed methodology includes a detailed analysis of threat modeling, which is crucial for identifying and mitigating potential cybersecurity risks. By conducting threat modeling, organizations can systematically assess vulnerabilities and implement appropriate countermeasures to enhance the security posture of automotive components. Furthermore, the paper discusses the integration of CAL into an existing cybersecurity framework, emphasizing the importance of continuous monitoring and improvement. The case study demonstrates how CAL values can be effectively utilized to prioritize cybersecurity efforts and allocate resources efficiently. Additionally, we append different cases to determine the correct CAL value based on test results, ensuring comprehensive validation and robustness of the cybersecurity measures. By incorporating CAL into the product life cycle, organizations can ensure that cybersecurity considerations are embedded throughout the development process, from initial concept to final deployment. This comprehensive approach not only enhances the security of automotive components but also contributes to the overall resilience of the vehicle against cyber threats.
Ghosh, SubhamKhader Batcha, Jashic
With the emergence of Software-Defined Vehicles (SDVs), more complex software and connectivity technologies are introduced to support new advanced use cases such as phone as a key, smart parking and vehicle management. However, complex software functionality and external connectivity also increase the attack surface of vehicles and its ecosystem. In this paper, we first perform a classification of recent automotive cybersecurity attacks. We further perform an analysis of these attacks and associated vulnerabilities considering the application of best practices of vulnerability management approaches including Common Vulnerability Scoring System (CVSS), Exploit Prediction Scoring System (EPSS), and Stakeholder-Specific Vulnerability Categorization (SSVC). CVSS is a standardized framework used to assign severity scores to known vulnerabilities and helps organizations prioritize vulnerability remediation based on severity. EPSS is a predictive model that estimates the probability of a vulnerability being exploited in the next 30 days and complements CVSS by focusing on real-world likelihood of exploitation rather than just severity. SSVC is a decision-making framework for vulnerability handling to help organizations make appropriate remediation decisions considering the specific situation based on, e.g., exploitation activity, mission prevalence and public well-being. We discuss the challenges and benefits of using these different vulnerability management approaches to help automotive organizations manage risks and prioritize handling of vulnerabilities. As auto manufacturers are responsible for the cybersecurity during the lifecycle of their fleet of vehicles, we stress the importance of analyzing and assessing vulnerabilities in a systemic way in order to timely address newly detected vulnerabilities with appropriate responses.
Oka, Dennis KengoVadamalu, Raja Sangili
With the increasing complexity and connectivity in modern vehicles, cybersecurity has become an indispensable technology. In the era of Software-Defined Vehicles (SDVs) and Ethernet-based architectures, robust authentication between Electronic Control Units (ECUs) is critical to establish a trust. Further, the cloud connected ECUs must perform authentication with backend servers. These authentication requirements often demand multiple certificates to be provisioned within a vehicle, ensuring secure communication between various combinations of ECUs. As a result, a single ECU may end up storing multiple certificates, each serving a specific purpose. This work proposes a method to limit the number of certificates required in a given ECU without compromising security. We introduce a Cross-Intermediate Certificate Authority (Cross-ICA) Trust Architecture, which enables the use of a single certificate per ECU for inter-ECU communication as well as backend server authentication. In this architecture, each ECU is issued a certificate from an Intermediate Certificate Authority (ICA), with all ICAs anchored to a common Root CA. The ICAs are structured based on the nature or domain of the ECU (e.g., infotainment, telematics, ADAS), while maintaining trust through the shared root. During the authentication handshake, the ECU presents its certificate chain. The receiving party (another ECU or backend server) verifies the chain up to the common root, thus establishing mutual trust, even if their certificates originate from different ICAs. The participating ECUs don’t need prior information about certificate chains of each other. This approach reduces certificate storage requirements, simplifies certificate management, and maintains strong security by leveraging a scalable trust model anchored to a unified root. The proposed method is primarily validated in a virtual environment using an OpenSSL implementation. Additionally, the approach is verified on a simulation setup involving two ECU and cloud connectivity, establishing mTLS with certificates issued by cross-signed Intermediate Certificate Authorities (ICAs).
Venugopal, VaisakhGoyal, YogendraRaja J, SolomonRai, AjayRath, Sowjanya
In recent years many automotive cybersecurity relevant regulations have been released and some have already started to come into effect. Moreover, some other regulations will come into effect in the next few years. These regulations provide requirements and guidance to automotive organizations with different degree of specifics. In this paper, we review a number of different cybersecurity relevant regulations such as UNR 155, UNR 156, AIS 189, AIS 190, GB 44495, GB 44496, EU Cyber Resilience Act, and BIS Final Rule. We break down and categorize these regulations based on their scope and highlight key areas relevant to different teams within the organizations. These key areas include Cybersecurity Management System (CSMS), Software Update Management System (SUMS), secure software development and software supply chain security, continuous cybersecurity activities (monitoring, incident response), and vulnerability disclosure and management. We then map responsibilities from the regulations to respective relevant teams such as cybersecurity team, software development team, IT team, legal/compliance and procurement. The purpose is to help clarify roles and responsibilities within the organization to ensure relevant teams are involved to meet the specific requirements. We further analyze the regulations to identify similarities as well as potential challenges for organizations when preparing their organizations in addressing multiple regulations. Examples we discuss in detail include incident reporting, security testing and Software Bill of Material (SBOM) management. As more regulations are coming into effect in the next coming years, organizations need to ensure that they are readily prepared to fulfill the necessary requirements to comply with relevant regulations.
Oka, Dennis KengoVadamalu, Raja Sangili
With the increasing connectivity of modern vehicles, cybersecurity threats have become a critical concern. Intrusion Detection Systems (IDS) play a vital role in securing in-vehicle networks and embedded vehicle computers from malicious attacks. This presentation shares about an IDS framework designed specifically for POSIX-based operating systems used in vehicle computers, leveraging system-level monitoring, anomaly detection, and signature-based methods to identify potential security breaches. The proposed IDS integrates lightweight behavioral analysis to ensure minimal computational overhead while effectively detecting unauthorized access, privilege escalation, communication interface monitoring etc. By employing a combination of rule-based and OS datapoints, the system enhances threat detection accuracy without compromising real-time performance. Practical series deployments demonstrate the effectiveness of this approach in mitigating cyber threats in automotive environments, ensuring safer and more resilient vehicle systems.
Shukla, SiddharthChatterjee lng, Avik
Computer vision has evolved from a supportive driver-assistance tool into a core technology for intelligent, non-intrusive occupant health monitoring in modern vehicles. Leveraging deep learning, edge optimization, and adaptive image processing, this work presents a dual-module Driver Health and Wellness Monitoring System that simultaneously performs fatigue detection and emotional wellbeing assessment using existing in-cabin RGB cameras without requiring additional sensors or intrusive wearables. The fatigue module employs MediaPipe-based facial and skeletal landmark analysis to track Eye Aspect Ratio (EAR), Mouth Aspect Ratio (MAR), head posture, and gaze dynamics, detecting early drowsiness and postural deviations. Adaptive, driver-specific thresholds combined with CAN-bus data fusion minimize false positives, achieving over 92% detection accuracy even under variable lighting and demographics. The emotional wellbeing module analyzes micro-expressions and facial action units to estimate stress, calmness, and agitation, contextualizing these states with fatigue indicators for holistic assessment. All computation occurs on the Jetson Nano edge platform with has a Quad-core ARM Cortex-A57 CPU and 128-core Maxwell GPU, optimized with TensorRT quantization for real-time operation (≤150 ms latency). The architecture ensures on-device privacy, aligning with GDPR and ISO/SAE 21434 cybersecurity principles. Compared with Tier-1 radar camera solutions, the proposed framework is fully software-driven, cost-efficient, and privacy-preserving. Field validation confirms strong correlation between model predictions and physiological HRV metrics. Future extensions include extreme fatigue detection and multimodal sensor fusion toward a self-adaptive, wellness aware vehicle ecosystem.
Iqbal, ShoaibImteyaz, Shahma
With the rapid advancement of connected vehicle technologies, infotainment Electronic Control Units (ECUs) have become central to user interaction and connectivity within modern vehicles. However, this enhanced functionality has introduced new vulnerabilities to cyberattacks. This paper explores the application of Artificial Intelligence (AI) in enhancing the cybersecurity framework of infotainment ECUs. The study introduces AI-powered modules for threat detection and response, presents an integrated architecture, and validates performance through simulation using MATLAB, CANoe, and NS-3. This approach addresses real-time intrusion detection, anomaly analysis, and voice command security. Key benefits include zero-day exploit resistance, scalability, and continuous protection via OTA updates. The paper references real-world automotive cyberattack cases such as OTA vulnerability patches, Connected Drive exploits, and Uconnect hack, emphasizing the critical need for AI-enabled proactive cybersecurity frameworks.
More, ShwetaKulkarni, ShraddhaKumar, PriyanshuGhanwat, HemantJoshi, Vivek
The integration of Internet of Things (IoT), Artificial Intelligence (AI), and Machine Learning (ML) has transformed various industries, offering substantial benefits. The application of these technologies in engine reliability testing has immense potential as they offer real-time monitoring and analysis of engine performance parameters. Engine reliability testing is vital for ensuring the safety, efficiency, and longevity of engines. Traditional methods are time consuming, expensive, and rely heavily on manual inspection and data analysis. This paper shows how IoT and ML technologies can enhance the efficiency of engine reliability testing. The paper includes the following case studies:
Yadav, Sanjay KumarKumar, PrabhakarR, DineshJoon, SushantRai, AyushTripathi, Vinay Mani
As vehicles transform into complex cyber-physical systems within Intelligent Transportation Systems (ITS), automotive cybersecurity has become a foundational pillar in securing safe, reliable, and trustworthy transportation. This paper examines cybersecurity challenges in connected and autonomous vehicles (CAVs), focusing on Vehicle-to-Everything (V2X) communications technologies, including Vehicle-to-Vehicle (V2V), Vehicle-to-Infrastructure (V2I), and Vehicle-to-Pedestrian (V2P), and critical systems like electronic control units (ECUs), battery management units (BMUs), and sensor fusion modules. Key vulnerabilities, such as remote hacking, denial-of-service (DoS) attacks, malware injection, and data breaches, threaten vehicle functionality, passenger safety, and privacy. Key protection mechanisms, including encryption, intrusion detection systems (IDS), cryptographic protocols, secure over-the-air (OTA) updates, and Advanced Artificial Intelligence (AI) and Machine Learning (ML) algorithms, enhance threat detection, anomaly monitoring, and adaptive security responses. Additionally, emerging blockchain-based security frameworks offer decentralized solutions for data integrity and secure transactions. For electric vehicles (EVs), lightweight and energy-efficient cybersecurity solutions are critical to securing EV-specific architectures. Global standardization efforts, including ISO/SAE 21434 and UN Regulation No. 155, are shaping industry best practices, ensuring interoperability and scalable security frameworks for next-generation vehicles. This review synthesizes research advancements from 2001 to 2024, identifying key challenges such as real-time threat mitigation, scalability, and adaptive security architectures. The paper aims to provide valuable insights for researchers, engineers, and policymakers, fostering the development of secure, resilient, and sustainable automotive ecosystems in an increasingly digitized transportation network.
Kumar, OmKumar, RajivSankar M, GopiHaregaonkar, Rushikesh Sambhaji
The proliferation of connectivity features (V2X, OTA updates, diagnostics) in modern two-wheelers significantly expands the attack surface, demanding robust security measures. However, the anticipated arrival of quantum computers threatens to break widely deployed publickey cryptography (RSA, ECC), rendering current security protocols obsolete. This paper addresses the critical need for quantum-resistant security in the automotive domain, specifically focusing on the unique challenges of two-wheeler embedded systems. This work presents an original analytical and experimental evaluation of implementing selected Post-Quantum Cryptography (PQC) algorithms, primarily focusing on NIST PQC standardization candidates (e.g., lattice-based KEMs/signatures like Kyber/Dilithium), on microcontroller platforms representative of those used in two-wheeler Electronic Control Units (ECUs) - typically ARM Cortex-M series devices characterized by limited computational power, memory (RAM/ROM), and strict real-time requirements. Our experimental study involved porting and optimizing PQC reference implementations for these constrained environments. We rigorously benchmarked key performance indicators, including key generation time, encapsulation/decapsulation speeds, signing/verification times, and memory footprint (stack usage, code size). The results demonstrate the feasibility of deploying specific PQC schemes, achieving practical execution times (e.g., key operations completing within tens to hundreds of milliseconds) and manageable memory overhead (fitting within typical MCU constraints) for securing functions like secure boot, firmware updates, and authenticated communication. Performance trade-offs between different PQC algorithms regarding speed, key/signature sizes, and memory consumption are analyzed. The significance of this contribution lies in providing the first quantitative performance data and feasibility analysis for PQC adoption within the specific context of two-wheeler embedded systems. These findings offer crucial insights for OEMs and suppliers planning the transition to quantum-safe security architectures, ensuring the long-term security and trustworthiness of connected two-wheelers against future cryptographic threats.
Mishra, Abhigyan
Threat Analysis and Risk Assessment (TARA) is a continuous activity, acting as a foundation of cybersecurity analysis for electrical and electronics automotive products. Existing TARA methodologies in the automotive domain exhibits challenges due to redundant and manual processes, particularly in handling recurring common assets across Electronic Control Units (ECUs) and functional domains. Two primary approaches observed for performing TARA are Manual-Asset-Centric TARA and Catalogue-Driven TARA. Manual-Asset Centric TARA is constructed from scratch by manually identifying the assets, calculating risks by likelihood, and impact determination. Catalogue-Driven TARA utilizes the precompiled likelihood and impact against identified assets. Both approaches lack standardized and modular mechanisms for abstraction and reuse. This results in poor scalability, increased efforts, and difficulty in maintaining consistency across vehicle platforms. The proposed method in this research overcomes such challenges, named as “MOSAIC-TARA”. It is a Modular, Scalable, Adaptive, Interoperable, Comprehensive TARA, decomposing a vehicle system into functional domains or ECUs, and further into its components. Each module is independently assessed and analyzed for potential threats, damage scenarios, and security goals, formulating the multiple TARA modules. These independent individual TARAs are then aggregated based on the architecture to derive ECU level TARA. The modularity of this method supports reusability of assessments across different ECUs, functional domains, and vehicle platforms. This enables optimized and efficient TARA tailored to different system configurations. Additionally, the presented approach introduces damage scenarios classification based on impact criticality, as the same component may lead to varying damage impact depending on the context. Thus, the TARA modules are developed for various levels of damage impacts, provides adaptability towards impact criticality of selected ECU or its functions. MOSIAC-TARA aligns with ISO/SAE 21434 and supports efficient reusable risk-driven design.
Goyal, YogendraSinha, SwatiSutar, SwapnilJaisingh, Sanjay
State Transport Units (STUs) are increasingly using electric buses (EVs) as a result of India's quick shift to sustainable mobility. Although there are many operational and environmental benefits to this development, like lower fuel prices, fewer greenhouse gas emissions, and quieter urban transportation, there are also serious cybersecurity dangers. The attack surface for potential cyber threats is expanded by the integration of connected technologies, such as cloud-based fleet management, real-time monitoring, and vehicle telematics. Although these systems make fleet operations smarter and more efficient, they are intrinsically susceptible to remote manipulation, data breaches, and unwanted access. This study looks on cybersecurity flaws unique to connected passenger electric vehicles (EVs) that run on India's public transit system. Electric vehicle supply equipment (EVSE), telematics control units (TCUs), over-the-air (OTA) update systems, and in-car networks (such as the Controller Area Network or CAN bus) are important areas of interest. Potential interruptions to vehicle functionality and passenger safety are examined in relation to common attack techniques such spoofing, data injection, denial-of-service (DoS), and remote code execution. In comparison to international standards like ISO/SAE 21434 and UNECE rules R155/R156, the report also assesses regulatory and compliance deficiencies in India. It lists the operational difficulties that Indian STUs encounter, including as antiquated infrastructure, a deficiency in cybersecurity knowledge, and a lack of established protocols. The paper suggests a plan for installing a Cybersecurity Management System (CSMS) in STU-operated EV fleets in order to reduce these threats. Strong incident response mechanisms, focused training initiatives, and the creation of cybersecurity standards tailored to India are among the recommendations. Implementing these measures will enhance the resilience of electric vehicle infrastructure against emerging cyber risks. Furthermore, collaboration between government agencies, industry stakeholders, and academic institutions is emphasized to ensure a comprehensive cybersecurity framework.
Mokhare, Devendra Ashok
The modern vehicle is no longer a mechanical appliance—it has transformed into a software-defined cyber-physical system, integrating OTA updates, cloud-connected diagnostics, V2X services, and telematics-driven personalization. While this evolution promises unprecedented value in consumer experience and fleet operations, it also surfaces a dramatically expanded and evolving attack perimeter, especially across safety-critical ECUs and communication buses. Cyber vulnerabilities have shifted from isolated IT threats to real-time, embedded exploits. Controller area network (CAN), the backbone of vehicle bus systems, remains intrinsically insecure due to its lack of authentication and encryption, making it highly susceptible to message injection and denial-of-service by low-cost tools. Similarly, OEM implementations of BLE-based passive entry systems have proven vulnerable to replay and spoofing attacks with minimal hardware. In the Indian context, the transition to connected mobility is advancing rapidly under national mandates such as FAME II, PM e-DRIVE, and the National Electric Mobility Mission Plan (NEMMP). However, field-level assessments of Indian and international vehicle models—including ICE cars, electric two-wheelers, and fleet EVs—reveal critical gaps in CAN architecture connected to critical ECUs, Cloud API and Endpoints and RF controls. Notably, many of these vulnerabilities materialized after vehicle homologation, propagating through OTA updates or third-party app integrations. This reality underscores the inadequacy of static, pre-market cybersecurity assessments in effectively mitigating operational risk. This paper introduces a novel, scalable methodology that addresses this critical gap by enabling empirical, attack-informed validation, aligned with both Indian priorities and international best practices
Shah, RavindraAwasthi, Vibhu VaibhavKarle, Ujjwala
The exponential growth of connected and autonomous vehicles has significantly escalated cybersecurity threats, compelling automotive Original Equipment Manufacturers (OEMs) to adopt robust and structured Cybersecurity Incident Response (CSIR) capabilities. Current automotive cybersecurity regulations, such as AIS 189 in India and UNECE WP.29 globally, mandate precise frameworks for proactive threat detection, timely response, and comprehensive incident documentation. This research presents an innovative, comprehensive CSIR framework specifically tailored to integrate seamlessly into OEM cybersecurity management processes. Leveraging a combination of real-time monitoring systems, structured threat categorization methodologies, and integrated escalation and communication protocols, the proposed CSIR framework ensures efficient incident handling aligned with stringent regulatory compliance. The framework encompasses advanced methodologies including Vehicle Security Operations Center (VSOC) integration for continuous monitoring, standardized incident classification based on severity and potential impact, and well-defined communication channels with national Computer Emergency Response Teams (CERTs) and regulatory authorities. By integrating this framework, OEMs can significantly elevate their cybersecurity resilience, strengthen stakeholder confidence, and effectively meet evolving global cybersecurity regulatory demands.
Chaudhary lng, VikashDesai, ManojChatterjee, AvikChatterjee lng, Avik
The escalating dependence of Autonomous Vehicles on Intelligent Transportation Systems (ITS) has highlighted the imperative for comprehensive security protocols to safeguard such vehicles against cyber threats. Intrusion Detection Systems (IDS’s) are pivotal in ensuring the protection of these systems by detecting and alleviating unauthorized access and nefarious activities. The German Traffic Sign Recognition Benchmark (GTSRB) database, which encompasses an extensive compilation of traffic sign imagery, functions as a vital asset for the advancement of machine learning-based IDS. This research elucidates an intrusion detection system (IDS) that employs machine learning algorithms to scrutinize the GTSRB database. The proposed IDS emphasize the preprocessing of the GTSRB dataset to extricate pertinent features that can be employed for the training of machine learning models. Research also focuses on model development with machine learning algorithms to classify traffic signs and discern anomalies suggestive of potential intrusions. The efficacy of the models is evaluated utilizing accuracy thereby ensuring that the IDS can consistently differentiate between benign and malicious activities. This inquiry contributes to the domain of intelligent transportation systems by establishing a resilient framework in autonomous vehicles for intrusion detection, thus bolstering the security of automated traffic management systems against prospective cyber threats. The results underscore the criticality of incorporating machine learning methodologies in real-time systems to proactively mitigate security vulnerabilities and preserve the integrity of traffic data.
Patil, KamaleshAkbar Badusha, A.Jadhav, SavitriGunale, Kishanprasad
ISO/SAE 21434 emphasizes comprehensive cybersecurity risk management throughout the automotive lifecycle. However, specific guidance on validating cybersecurity measures at the production level remains limited. This paper addresses the gap in production-stage validation, particularly after End-of-Line (EOL) flashing, which includes configurations of security hardware and software protection (e.g., hardware register configuration, Debug and P-flash password settings etc.) Current automotive cybersecurity validation methods, despite adherence to ISO/SAE 21434, lack specific procedures for the production stage. The existing system-level validation using the ASPICE V-model (e.g., SWE.6, SYS.5) does not ensure the integrity and functionality of cybersecurity features in the final manufactured unit post-EOL flashing. This gap poses a risk of vulnerabilities being introduced during the EOL process, compromising critical security measures. To mitigate the cybersecurity risks in production units, particularly the binary which has been introduced during End-of-Life (EOL) flashing, we propose a dedicated testing phase on the right side of the V-cycle. This phase of testing will be focused on identifying and resolving vulnerabilities stemming from EOL flashing processes, such as incorrect memory addresses or erroneous configuration values to activate the cybersecurity protection. The current ASPICE V-cycle process lacks dedicated validation for software flashed via EOL procedures. This proposal addresses this critical gap by advocating for dedicated testing that will verify the integrity of hardware & Software Cybersecurity configuration (example: UCB addresses, values, DEBUG, BMHD passwords etc.,). By implementing this validation process, we aim to substantially strengthen the overall cybersecurity solutions in production units. We have defined the necessary verification criteria and test cases and developed a performance testing strategy for the production unit testing stage. This strategy aims to ensure the robustness and reliability of cybersecurity measures in the final production units.
Chakraborty, SuchetaKulanthaisamy, NagarajanSankar, Ganesh
Commercial vehicles form the backbone of global supply chains. In India, the commercial vehicle (CV) industry is at a transformative crossroads, evolving from traditional hardware-centric models to advanced, software-defined architectures. Central to this shift are Software-Defined Vehicles (SDVs) and Automotive Software-as-a-Service (SaaS), catalysing a move toward intelligent, connected, and highly productive mobility solutions. With the Indian CV market surpassing $50 billion in 2024 and witnessing robust growth due to expanding e-commerce, infrastructure projects and regulatory evolution. Indian original equipment manufacturers (OEMs) are spearheading this revolution. This paper presents a comprehensive analysis of the technological enablers, monetization strategies, distinct challenges and opportunities encountered by Indian OEMs during their shift toward SDVs and automotive SaaS based business models. This research also examines the most important technical pillars underpinning next-generation automotive ecosystem creation and these pillars are centralized computing infrastructures, embedded cloud integration, efficient over-the-air (OTA) update engines and enhanced cybersecurity models designed to protect larger numbers of connected vehicles are observed. This work explains, from a financial standpoint, the new and innovative methods in which OEMs and technology providers are leveraging SDVs and SaaS to generate new revenue streams. The prominent strategies being debated are Feature-on-Demand (FoD) services, subscription-based services based on different functionalities and features, the creation of dynamic in-vehicle app ecosystems, data monetization opportunities based on privacy regulations and flexible pay-per-use models. Additionally, the changing paradigm of Mobility-as-a-Service (MaaS) model is comprehensively analysed in terms of its impact on the industry of the future. Yet, this revolutionary process is plagued by a number of challenges. The paper offers a critical analysis of concerns like the necessity of achieving widespread customer acceptance of new service models, the complexities of complying with diverse data privacy regulations.
Saini, GouravJahagirdar, ShwetaKhandekar, Dhiraj Baburao
This paper presents a comprehensive technical review of the Software-Defined Vehicle (SDV), a paradigm that is fundamentally reshaping the automotive industry. We analyze the architectural evolution from distributed Electronic Control Units (ECUs) to centralized zonal compute platforms, examining the critical role of Service-Oriented Architectures (SOA), the AUTOSAR standard, and virtualization technologies in enabling this shift. A comparative analysis of leading High-Performance Computing (HPC) platforms, including NVIDIA DRIVE, Tesla FSD, and Qualcomm Snapdragon Ride, is conducted to evaluate the silicon foundation of the SDV. The paper further investigates key enabling technologies such as Over- the-Air (OTA) updates, Digital Twins, and the integration of Artificial Intelligence (AI) for applications ranging from predictive maintenance to software-defined battery management. We scrutinize the competing V2X communication standards (DSRC vs. C-V2X) and address the paramount challenges of functional safety (ISO 26262) and cybersecurity (ISO/SAE 21434) in this new landscape. Finally, we identify open research challenges, ethical considerations, and the future trajectory of SDVs toward fully AI-defined, intelligent, and connected mobility.
Ahmad, AqueelHemanth, KhimavathKumar, OmKumar, RajivHaregaonkar, Rushikesh Sambhaji
This comprehensive research presents an in-depth analysis of communication protocols essential for implementing fast charging systems in India's rapidly expanding electric two-wheeler and three-wheeler market. As India witnesses unprecedented growth in electric mobility, with two-wheelers representing over 95% of current EV sales, the establishment of standardized, secure, and efficient charging protocols becomes paramount for widespread adoption. This study examines the current landscape of AC charging methodologies, evaluates the technical and economic feasibility of DC fast charging implementation, and provides detailed comparative analysis of existing international standards including IS 17017-25, IS 17017-31, ChaoJi, and CCS 2.0. The research concludes with strategic recommendations for developing cyber-secure, cost-effective charging infrastructure specifically tailored to meet India's unique market requirements and operational constraints.
Uthaman, SreekumarMulay, Abhijit B
The increasing adoption of electric vehicles (EVs) has raised the importance of secure communication between EVs and Electric Vehicle Supply Equipment (EVSE). As EV infrastructure rapidly evolves, cybersecurity threats targeting the vehicle-charger interface pose major risks to user safety, data integrity, and operational continuity. This paper presents an overview of existing EV-EVSE communication standards and explores their associated vulnerabilities. We identify potential cyber threats, including man-in-the-middle attacks, replay attacks, and protocol spoofing, that could compromise the security of EV charging systems. The study proposes an enhanced cybersecurity framework incorporating session authentication, and anomaly detection techniques to fortify EV-EVSE communication. The proposed mitigation strategies aim to ensure secure, reliable, and resilient charging infrastructure essential for the widespread adoption of electric mobility.
Uthaman, SreekumarPatil, Urmila
Items per page:
1 – 50 of 629