OTA Will Drive Cybersecurity Programs

Connecting vehicles with the Internet means that cybersecurity is now a necessity that must be designed into nearly every piece of automotive hardware and software. Security schemes will have to include techniques for updating security software as threats evolve.
Vehicles are becoming part of the Internet of Things (IoT), but they’re also joining the Internet of Threats, Faye Francy told WCX attendees during a panel dubbed “CyberSecurity 2.0 – Collaboration, Incident Response and Automation.” Francy heads up the Auto-ISAC (Information Sharing and Analysis Center), which was formed by many OEMs and Tier 1s to work together to thwart hackers.
Panelists agreed that over-the-air (OTA) updating is a critical aspect of any cybersecurity program, since hackers will continually find new ways to attack connected products.
“OTA updating is absolutely the most important things you can do in cybersecurity,” said Justin Cappos, a cybersecurity expert from New York University.
OEMs have been updating software through dealerships for years. That model probably won’t work given the need to regularly update cybersecurity software as hackers try new techniques for exploiting vulnerabilities. Some companies plan to start OTA programs in areas like infotainment before moving into powertrains and safety systems.
“We’re starting with modules that aren’t in the critical path,” said General Motors’ Chief Product Cybersecurity Officer Kevin Tierney. “We need to make sure those connections are secure. Over time, we will go into safety critical modules.”
Many automotive companies have relied on proprietary technologies to safeguard software, but that approach may not work for cybersecurity. Do-it-yourself architectures for protecting over-the-air updates might have more vulnerabilities than protective schemes that have been reviewed by hundreds or thousands of engineers who attempt to breach the barricades.
“There are ways to do it right, and ways to do it wrong, so why not use a standard way that’s used by a lot of people?” said Dr. Andre Weimerskirch, VP Global Cyber Security at Lear Corp. “Companies need to have a software architecture that lets them update the majority of software without needing to recertify it.”
Top Stories
INSIDERPower
Supersonic X-59 Completes Cruise Control Engine Speed Test Ahead of First Flight
INSIDERManufacturing & Prototyping
3D-Printed C-17 Replacement Part Saves Thousands for Air Force
INSIDERCommunications
Aitech’s New Palm-Sized Satellite Enables Space-Based AI Processing
INSIDERManufacturing & Prototyping
Bombardier is Digitally Upgrading its Aircraft Design, Engineering and...
INSIDERPower
Navy Proves Cold-Gas Approach in Hypersonic Launch Test
PodcastsDefense
Engineering the EL9: Electra's Ultra Short Hybrid-Electric Aircraft
Webcasts
Materials
Optimizing Electric Powertrains: Advanced Materials for Performance, Safety,...
Imaging
Breakthrough in Infrared and Visible Imaging: One Dataset with...
Test & Measurement
Improving Rocket and Flight Vehicle Testing Under Capital...
AR/AI
Advancing Automotive Manufacturing with Digital Twins
Defense
Powering NewSpace Missions: Navigating the Cost vs. Reliability...
Electronics & Computers
Solving Thermal Challenges in Defense: The Role of ECUs and...