Browse Topic: Cybersecurity
1Systems level and integration testing are an integral part of the design and development of Automated Vehicles (AVs). Measurement science plays a pivotal role in testing to ensure the safe and efficient operation of AVs. This science establishes a common understanding of the units of measurement, crucial in linking human activities. This article describes the significance of measurement in studying interactions between key system technologies in AVs, including AI for perception, sensing, communications, and cybersecurity. To address the complexities of these interactions, a novel, adaptable, and interactive framework called the System Technology Interaction Model (STIM) is introduced. STIM considers both designed and emergent interactions between these system technologies, allowing AV developers to explore tailored experiments with the flexibility of filtering for focused testing. The framework currently models system interactions statically, not in real-time, to define potential relationships and influences during the design phase. The novelty of this framework comes from providing a holistic evaluation that captures testing of interactions between modules in addition to component-level testing, while other frameworks focus on testing individual component behaviors. It also assesses the equality of two interactions, meaning it ensures that two interactions behave the same way for consistent results. Moreover, the framework serves as a valuable tool for AV designers and safety regulators to aid in establishing robust design and assessment approaches. This work highlights the need for a common framework to thoroughly test AVs and gain a holistic understanding of system interactions. Finally, the framework aims to understand how to mitigate potential influences leading to AV malfunctions to advance the development and deployment of safe and reliable Automated Vehicles. The work focuses on level 1 and level 4 automated driving features to simplify the work, although it can be from level 1 to level 5. Although framework performance is inherently difficult to quantify, this framework’s performance can be reflected through its ability to accurately capture system interactions for improved AV design and support a broader usability among AV stakeholders. In the future, the framework can be expanded to include additional elements, such as infrastructure or other vehicles, to analyze information provided to AVs, allowing experts from various domains to collaborate, create similar models, integrate them when feasible, and model the interactions in real-time.
It's not difficult to find warnings about the dangers of AI. The news that Anthropic's new AI tool is too dangerous for the public due to its alleged hacking capabilities should be of concern to every company making software. That includes automakers. Software has been part of the vehicles in our driveways for decades. In the past few years, even more so, with the push for software-defined vehicles (SDV). At SAE's 2026 WCX conference, a group of cybersecurity professionals from the vehicle industry discussed what AI and SDVs mean for current and future vehicles and how their jobs are about to get simultaneously easier and more difficult.
The useability of development processes in the automotive sector has decreased in the past years to a level at which their application and true benefit to is being questioned. Such degradation can be attributed to new additions to the processes and introduction of FuSa and Cybersecurity standards. The processes try to keep up with the shift from the traditional ‘plan–implement–test–roll-out' methodology to more agile methods. In addition, process departments typically in charge of these processes, focus on compliance to the letter of the standard to achieve certification, often with little thought to the actual implementation and the process they will be used by their engineering teams. Process growth to meet the needs of new and more complex technologies often mandates the use of new tools, which if implemented incorrectly can lead to unnecessary bureaucracy and additional overheads. Furthermore, the language of these new processes is in a form from assessor, making it difficult for an engineer to understand, interpret and implement. As a result, engineers become annoyed, losing productivity and motivation when working with what they perceive as burdensome standards, that simply exist to slow development. This has a huge impact on the competitiveness of companies especially in markets that are facing existential threats from internal and external pressures such as the automotive industry. Against popular belief, the application of generative AI (and large language models) will not solve the problem. On the contrary, it risks automating complex processes in the same unfamiliar language and creating documents to serve process overhead, rather than engineering development. This paper presents inefficiencies in the current state-of-the art processes used in the automotive sector and proposes a structured approach that increases the efficiency of automotive software development. It does so by documenting and implementing development processes based on how engineers actually perform their work. In the second step the adjustments that are necessary to ensure compliance of the product with industry standards are made. Such an approach produces efficient, compact and compliant process definition.
The automotive industry is evolving from a reactive, independently self-determined approach to cybersecurity, complicated by a complex supply chain. Over time, this has resulted in a fragmented industry comprised of any number of proprietary solutions verses a standardized, regulated paradigm to facilitate a platform-oriented approach. This document, an update on collaborative work from the SAE Vehicle Electrical Hardware Security Task Force (TEVEES18B) and GlobalPlatform Automotive Task Force, outlines this transition strategy. An extensible number of additional examples of use cases of Global Platform Technologies are explored in this document.
Modern vehicles require sophisticated, secure communication systems to handle the growing complexity of automotive technology. As in-vehicle networks become more integrated with external wireless services, they face increasing cybersecurity vulnerabilities. This paper introduces a specialized Proxy based security architecture designed specifically for Internet Protocol (IP) based communication within vehicles. The framework utilizes proxy servers as security gatekeepers that mediate data exchanges between Electronic Control Units (ECUs) and outside networks. At its foundation, this architecture implements comprehensive traffic management capabilities including filtering, validation, and encryption to ensure only legitimate data traverses the vehicle's internal systems. By embedding proxies within the automotive middleware layer, the framework enables advanced protective measures such as intrusion detection systems, granular access controls, and protected over-the-air (OTA) update channels. This strategy enhances both data security and system isolation, creating protective boundaries between critical vehicle operations and potential external attacks. The architecture particularly excels in supporting Vehicle-to-Everything (V2X) connectivity, facilitating seamless information exchange between vehicles, roadside infrastructure, and pedestrians. This capability is essential for enhancing roadway safety, optimizing traffic flow, and supporting autonomous driving technologies. The system incorporates dedicated proxy modules for specialized protocols including Trivial File Transfer Protocol (TFTP), Diagnostic Over Internet Protocol (Doip), and Message Queuing Telemetry Transport (MQTT), each fulfilling specific functions in vehicle diagnostics, software updates, and telemetry data management. Performance evaluations will measure latency and throughput metrics to validate the architecture's efficiency and reliability. The framework's modular design aims to provide scalability and adaptability to accommodate both technological advancements and emerging security challenges. The proxy-based security framework presented offers a holistic and forward-looking approach to safeguarding in-vehicle networks. It provides automotive manufacturers with the tools to develop connected vehicles that combine intelligence and efficiency with robust protection against diverse cybersecurity threats.
Automotive Over-the-Air (OTA) software updating has become a cornerstone of the modern connected vehicle, enabling manufacturers to remotely deploy bug fixes, security patches, and new features. However, this convenience comes with significant cybersecurity challenges. This paper provides a detailed examination of automotive OTA update security and the software store (software Applications & services store) mechanisms. I discuss the current industry standards and regulations, notably ISO/SAE 21434 and the United Nations Economic Commission for Europe (UNECE) regulations UN R155 (cybersecurity) and UN R156 (software updates) and explain their relevance to secure OTA and software update management. I then explored the Uptane framework, an open and widely adopted architecture specifically designed to secure automotive OTA updates. Next, OTA-specific threat models are analyzed, detailing potential attack vectors and corresponding mitigation strategies. Real-world case studies are presented to illustrate both the risks and the successful deployment of secure OTA systems in the industry. I conclude with insights into best practices for implementing a robust, compliant OTA update ecosystem, emphasizing a global perspective on regulations and the need for continuous vigilance throughout the vehicle lifecycle.
With the increasing connectivity of modern vehicles, cybersecurity threats have become a critical concern. Intrusion Detection Systems (IDS) play a vital role in securing in-vehicle networks and embedded vehicle computers from malicious attacks. This presentation shares about an IDS framework designed specifically for POSIX-based operating systems used in vehicle computers, leveraging system-level monitoring, anomaly detection, and signature-based methods to identify potential security breaches. The proposed IDS integrates lightweight behavioral analysis to ensure minimal computational overhead while effectively detecting unauthorized access, privilege escalation, communication interface monitoring etc. By employing a combination of rule-based and OS datapoints, the system enhances threat detection accuracy without compromising real-time performance. Practical series deployments demonstrate the effectiveness of this approach in mitigating cyber threats in automotive environments, ensuring safer and more resilient vehicle systems.
With the rapid advancement of connected vehicle technologies, infotainment Electronic Control Units (ECUs) have become central to user interaction and connectivity within modern vehicles. However, this enhanced functionality has introduced new vulnerabilities to cyberattacks. This paper explores the application of Artificial Intelligence (AI) in enhancing the cybersecurity framework of infotainment ECUs. The study introduces AI-powered modules for threat detection and response, presents an integrated architecture, and validates performance through simulation using MATLAB, CANoe, and NS-3. This approach addresses real-time intrusion detection, anomaly analysis, and voice command security. Key benefits include zero-day exploit resistance, scalability, and continuous protection via OTA updates. The paper references real-world automotive cyberattack cases such as OTA vulnerability patches, Connected Drive exploits, and Uconnect hack, emphasizing the critical need for AI-enabled proactive cybersecurity frameworks.
The integration of Internet of Things (IoT), Artificial Intelligence (AI), and Machine Learning (ML) has transformed various industries, offering substantial benefits. The application of these technologies in engine reliability testing has immense potential as they offer real-time monitoring and analysis of engine performance parameters. Engine reliability testing is vital for ensuring the safety, efficiency, and longevity of engines. Traditional methods are time consuming, expensive, and rely heavily on manual inspection and data analysis. This paper shows how IoT and ML technologies can enhance the efficiency of engine reliability testing. The paper includes the following case studies:
Items per page:
50
1 – 50 of 629