SlideShare a Scribd company logo
Automotive Security:
Challenges, Standards and
Solutions
Alexander Much
2016-09-14
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Agenda
2
• Safety, Security, ?
• Related Standards and Activities
• Solutions
• Summary
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Driver´s fears are being fueled by recent news
• a
3
Connected Cars
(new opportunities
for hackers)
New Autonomous
Driving Concepts
(and failures)
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Opposing Goals?
Automotive Security: Challenges, Standards and Solutions
Connected Car offers new business models for hackers?
• a
4CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Autonomous theft?
55CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
;-)
6
© xkcd.com, https://xkcd.com/1559/
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
“Trustworthy Computing” Memo
From: Bill Gates
Sent: Tuesday, January 15, 2002 5:22 PM
To: Microsoft and Subsidiaries: All FTE
Subject: Trustworthy computing
When we face a choice between adding features and resolving
security issues, we need to choose security. We must lead the
industry to a whole new level of Trustworthiness in
computing. […]
Trustworthy Computing is the highest priority for all the
work we are doing. […]
Key aspects include: […] Availability, […] Security, […]
Privacy.
Do we have similar challenges?
7
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
The Evolution of Car Hacking
88
Increasing digitalization
and digital integration
Hypothetical
vulnerabilities identified
Regular security breaches
with severe damages
Security threats become
relevant in practice
Security
Issues
Source: escrypt
Automotive Security: Challenges, Standards and Solutions
Dependability
9
Important:
• safety != reliability
• safety != security
• safety != availability
The challenge: balancing „ilities“.
Safety << Security!
Must-read paper: „Basic Concepts and
Taxonomy of Dependable and Secure
Computing“
https://www.nasa.gov/pdf/636745main_day_3-
algirdas_avizienis.pdf
Also look at: Architecture Tradeoff Method, SEI:
https://resources.sei.cmu.edu/asset_files/TechnicalRepo
rt/2000_005_001_13706.pdf
Dependability
Attributes
Security
Availability
Reliability
Safety
Integrity
Maintainability
Threats
Fault
Error
Failure
Means
Prevention
Removal
Forecasting
Tolerance
Documentation
https://en.wikipedia.org/wiki/Dependability
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Entry Points
10
Internet connection
Bluetooth connection
Wireless key
Tire pressure monitor
Remote start
Remote HVAC
WiFi Hotspot
Car2Infrastructure
Car2Car
eCall
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Excursion: Legal
Key quotes for security from 53. Goslaer Verkehrsgerichtstag, 2015-01:
„Zur Klärung von Haftungsansprüchen nach Schadensfällen in jeglichem
automatisierten Fahrbetrieb müssen Systemhandlungen und Eingriffe des Fahrers
beweissicher (!) dokumentiert werden.“
 tamper-resistant black-box (individual ECUs, function and system level)
„Datenschutz und Datensicherheit sowie Transparenz für den Nutzer sind dabei zu
gewährleisten.“
„Gegen Manipulationen von außen ist entsprechend dem Stand der Technik
Vorsorge zu treffen.“
 tamper-resistant devices and communication, authenticity, privacy, etc.
On the horizon: the US may mandate such requirements.
11
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Related Standards and Activities
• NIST, FIPS, etc.
• CERT (coding standards and more)
• ISO 27000 (wikipedia)
• RTCA/DO-326 (avionics)
• IEC 62443 (primarily automation)
• CMMI (Security by Design with CMMI v1.3, from Siemens)
• Microsoft SDL (Security Development Lifecycle)
• EVITA (research project)
• BMW group standard (GS 95014, 2015-02)
• SAE J3061 (to be published on 2015-12-03)
• OpenSAMM (Software Assurance Maturity Model)
(4 additional processes, similar to e.g. ISO 15504-10
• … and probably many more
12
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Excerpt from J3061 activities
• Tailors a security process framework from the ISO 26262 process framework
 Compatibility of the lifecycle and processes
• Goal-based rather than predictive
• Identifies methods and tools to facilitate the application of the process, e.g.
‒ Attack trees
‒ Penetration testing
‒ TARA methods (Thread And Risk Analysis)
• Published on 2015-12-03 with a webcast:
“The World’s First Standard on Automotive Cybersecurity.”
13
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Safety & Security: Process Model
Coordination needed between safety and security experts in relevant phases.
Key capability: systems engineering.
Safety & Security are system aspects (“emerging properties”, “speciality engineering”).
14
© Bosch, S. Kriso, M. Ihle, „Automotive Security im Kontext der Funktionalen Sicherheit“,
VDI / VW Gemeinschaftstagung „Automotive Security“, 2015-10-21
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
The “System”
Defining the system
boundaries is complex
in development as well
as during operations.
Systems are dynamic:
assumptions made
during development
may be false during
operations.
15
© Nancy Leveson, Engineering a Safer World (free download)
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Extension of the Life-Cycle
• Automotive SPICE strongly focuses on development.
• ISO 15504:2006 contains OPE.1 – Operational use, 5 base practices.
IMHO: rarely used.
• ISO 26262:2011 part 7 chapter 6: “operation, service and decommissioning”.
3 pages, fairly abstract.
• Security needs constant field monitoring of all stakeholders:
‒ Safety: a “static” hazard model
‒ Security: a “dynamic” threat model
• Security leads to a higher frequency of updates:
 maintainability, changeability is a key factor
• Incidents will happen => security is only mastered with a plan for response!
16
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
OTA & Quality: A “Warning”
• OTA offers many opportunities, including business models, etc.
• OTA will fundamentally change how we look at function deployment.
• OTA partially lowers SOP “pressure”:
“we’ll add / fix it later”
• Easy updates have lead to crappy software in other domains.
• The SPICE community needs to be aware of this fact!
17
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Example: Microsoft SDL
• Core Security Training
• Establish Security and Privacy
Requirements
• Create Quality Gates / Bug Bars
• Perform Security and Privacy Risk
Assessments
• Establish Design Requirements
• Attack Surface Analysis / Reduction
• Use Threat Modeling
• Use Approved Tools
18
• Deprecate Unsafe Functions
• Perform Static Analysis
• Perform Dynamic Analysis
• Fuzz Testing
• Attack Surface Review
• Create an Incident Response Plan
• Conduct Final Security Review
• Certify Release and Archive
• Execute Incident Response Plan
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Example: OpenSAMM
19
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Example: SAE J3061
20
Potential Communications Paths
During the Product
Development
(software level) Activities
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Secure System Layers
21
Secure
Environment
Secure External
Comm.
& Interfaces
Secure Network
Segmentation
Secure
OnBoard
Communication
Secure
Platform
Secure Boot
Secure Hardware Element
Secure Update / Diagnostics
- Applications
- Flashware
Separation / Isolation
- Memory Protection
- Scheduling Policies
- Access Control
AUTOSAR SecOC
Ethernet Security
Domain Separation
Trust Zones
IDS/ADS
Firewall
Secure External Channels
- TLS
Secure Logging Agent
Secure Backend Infrastructure
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Possible Solutions (from Os side)
22
Core PartitioningPure Autosar
Hypervisor
App App
Core 1
ECU
Core 2
AUTOSAR
Performance
Platform
App App
Core 1
ECU
Core 2
AUTOSAR
Performance
Platform
App App
Core 1
ECU
Core 2
AUTOSAR
Hypervisor
Performance Platform
App App
Core 1
ECU
Core 2
Microcontroller Partitioning
Performance
Platform
App App
Micro 1
ECU
Micro 2
AUTOSAR
Pure Performance
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Reference Architecture for Safe & Secure Platform
23
OS
(opt.)
Bootloader /
Flasher
ECUECU
Ethernet, FlexRay, CAN, LIN
OS
RTE
Applications
AUTOSAR
Hardware
Hardware Security
Module (HSM)
CSM
CryHSM
SecOC
Application Bootloader/Flasher
Authentication
SW signature
verification
Anti theft
SW as a
product
Milage prot.
Secure Boot
Intrusion Det.
EB Software
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Automotive Security: Challenges, Standards and Solutions
Summary (and opinion)
Processes & standards:
Standardization for security similar to ISO 26262 is needed, which forms a
consensus in the automotive domain.
Safety, security, reliability are system aspects that need to be balanced.
 They are all part of the “quality” of the product.
We need assessors who are technical experts of the systems they assess.
 “Simple” process and document checking won’t be enough.
The SPICE community needs to co-ordinate specialty engineering audits.
Systems engineering needs to be established within organizations.
24
Contact us! automotive.elektrobit.com
alexander.much@elektrobit.com
CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.

More Related Content

What's hot

Public policy aspects of Connected and Autonomous Vehicles
Public policy aspects of Connected and Autonomous VehiclesPublic policy aspects of Connected and Autonomous Vehicles
Public policy aspects of Connected and Autonomous Vehicles
Bill Harpley
 
Connected & Driverless vehicles: the road to Safe & Secure mobility?
Connected & Driverless vehicles: the road to Safe & Secure mobility?Connected & Driverless vehicles: the road to Safe & Secure mobility?
Connected & Driverless vehicles: the road to Safe & Secure mobility?
Bill Harpley
 
Cybersecurity in the Age of the Everynet
Cybersecurity in the Age of the Everynet   Cybersecurity in the Age of the Everynet
Cybersecurity in the Age of the Everynet
Bill Harpley
 
Introduction to Connected Cars and Autonomous Vehicles
Introduction to Connected Cars and Autonomous VehiclesIntroduction to Connected Cars and Autonomous Vehicles
Introduction to Connected Cars and Autonomous Vehicles
Bill Harpley
 
Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18
Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18
Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18
Mark Goldstein
 
The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19
Mark Goldstein
 
5 Autonomous Cars Trends Everyone Should Know About In 2019
5 Autonomous Cars Trends Everyone Should Know About In 20195 Autonomous Cars Trends Everyone Should Know About In 2019
5 Autonomous Cars Trends Everyone Should Know About In 2019
Bernard Marr
 
The Internet of Flying Things - Part 2
The Internet of Flying Things - Part 2The Internet of Flying Things - Part 2
The Internet of Flying Things - Part 2
Michael Denis
 
Autonomous Vehicles: Technologies, Economics, and Opportunities
Autonomous Vehicles: Technologies, Economics, and OpportunitiesAutonomous Vehicles: Technologies, Economics, and Opportunities
Autonomous Vehicles: Technologies, Economics, and Opportunities
Jeffrey Funk
 
ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18
ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18
ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18
Mark Goldstein
 
Future of autonomous vehicles initial perspective - 8 october 2018
Future of autonomous vehicles   initial perspective - 8 october 2018Future of autonomous vehicles   initial perspective - 8 october 2018
Future of autonomous vehicles initial perspective - 8 october 2018
Future Agenda
 
Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18
Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18
Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18
Mark Goldstein
 
20170122 MEETUP on autonomous vehicles
20170122 MEETUP on autonomous vehicles20170122 MEETUP on autonomous vehicles
20170122 MEETUP on autonomous vehicles
Brussels Legal Hackers
 
CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18
CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18
CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18
Mark Goldstein
 
Designing Roads for AVs (autonomous vehicles)
Designing Roads for AVs (autonomous vehicles)Designing Roads for AVs (autonomous vehicles)
Designing Roads for AVs (autonomous vehicles)
Jeffrey Funk
 
The car of the future @ International Automotive Breakfast Seminar 2013
The car of the future @ International Automotive Breakfast Seminar 2013The car of the future @ International Automotive Breakfast Seminar 2013
The car of the future @ International Automotive Breakfast Seminar 2013
ITKAM Camera di Commercio Italiana per la Germania
 
Autonomous vehicles: Plotting a route to the driverless future
Autonomous vehicles: Plotting a route to the driverless futureAutonomous vehicles: Plotting a route to the driverless future
Autonomous vehicles: Plotting a route to the driverless future
Accenture Insurance
 
Future mobile networks connected and autonomous cars
Future mobile networks  connected and autonomous carsFuture mobile networks  connected and autonomous cars
Future mobile networks connected and autonomous cars
lammya aa
 
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Forth
 
AircraftIT MRO Journal Vol 3.3 Paper or Plastic?
AircraftIT MRO Journal Vol 3.3 Paper or Plastic?AircraftIT MRO Journal Vol 3.3 Paper or Plastic?
AircraftIT MRO Journal Vol 3.3 Paper or Plastic?
Michael Denis
 

What's hot (20)

Public policy aspects of Connected and Autonomous Vehicles
Public policy aspects of Connected and Autonomous VehiclesPublic policy aspects of Connected and Autonomous Vehicles
Public policy aspects of Connected and Autonomous Vehicles
 
Connected & Driverless vehicles: the road to Safe & Secure mobility?
Connected & Driverless vehicles: the road to Safe & Secure mobility?Connected & Driverless vehicles: the road to Safe & Secure mobility?
Connected & Driverless vehicles: the road to Safe & Secure mobility?
 
Cybersecurity in the Age of the Everynet
Cybersecurity in the Age of the Everynet   Cybersecurity in the Age of the Everynet
Cybersecurity in the Age of the Everynet
 
Introduction to Connected Cars and Autonomous Vehicles
Introduction to Connected Cars and Autonomous VehiclesIntroduction to Connected Cars and Autonomous Vehicles
Introduction to Connected Cars and Autonomous Vehicles
 
Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18
Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18
Phoenix Mobile & Emerging Tech Festival Autonomous Vehicles Presentation 11/3/18
 
The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19The Autonomous Revolution of Vehicles & Transportation 6/12/19
The Autonomous Revolution of Vehicles & Transportation 6/12/19
 
5 Autonomous Cars Trends Everyone Should Know About In 2019
5 Autonomous Cars Trends Everyone Should Know About In 20195 Autonomous Cars Trends Everyone Should Know About In 2019
5 Autonomous Cars Trends Everyone Should Know About In 2019
 
The Internet of Flying Things - Part 2
The Internet of Flying Things - Part 2The Internet of Flying Things - Part 2
The Internet of Flying Things - Part 2
 
Autonomous Vehicles: Technologies, Economics, and Opportunities
Autonomous Vehicles: Technologies, Economics, and OpportunitiesAutonomous Vehicles: Technologies, Economics, and Opportunities
Autonomous Vehicles: Technologies, Economics, and Opportunities
 
ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18
ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18
ADOT Road to the Future Autonomous Vehicles Presentation 9/27/18
 
Future of autonomous vehicles initial perspective - 8 october 2018
Future of autonomous vehicles   initial perspective - 8 october 2018Future of autonomous vehicles   initial perspective - 8 october 2018
Future of autonomous vehicles initial perspective - 8 october 2018
 
Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18
Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18
Aerospace Arizona Summit Autonomous Vehicles Presentation 11/8/18
 
20170122 MEETUP on autonomous vehicles
20170122 MEETUP on autonomous vehicles20170122 MEETUP on autonomous vehicles
20170122 MEETUP on autonomous vehicles
 
CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18
CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18
CSA SW & (ISC)2 Phoenix Autonomous Vehicles Presentation 10/16/18
 
Designing Roads for AVs (autonomous vehicles)
Designing Roads for AVs (autonomous vehicles)Designing Roads for AVs (autonomous vehicles)
Designing Roads for AVs (autonomous vehicles)
 
The car of the future @ International Automotive Breakfast Seminar 2013
The car of the future @ International Automotive Breakfast Seminar 2013The car of the future @ International Automotive Breakfast Seminar 2013
The car of the future @ International Automotive Breakfast Seminar 2013
 
Autonomous vehicles: Plotting a route to the driverless future
Autonomous vehicles: Plotting a route to the driverless futureAutonomous vehicles: Plotting a route to the driverless future
Autonomous vehicles: Plotting a route to the driverless future
 
Future mobile networks connected and autonomous cars
Future mobile networks  connected and autonomous carsFuture mobile networks  connected and autonomous cars
Future mobile networks connected and autonomous cars
 
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
Adrian Pearmine, DKS Associates - Connected & Autonomous Vehicles 101 (Octobe...
 
AircraftIT MRO Journal Vol 3.3 Paper or Plastic?
AircraftIT MRO Journal Vol 3.3 Paper or Plastic?AircraftIT MRO Journal Vol 3.3 Paper or Plastic?
AircraftIT MRO Journal Vol 3.3 Paper or Plastic?
 

Viewers also liked

20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
Alexander Much
 
Automotive security (cvta)
Automotive security (cvta)Automotive security (cvta)
Automotive security (cvta)
Alan Tatourian
 
Full Circle: The Rise of Vehicle-Installed Telematics
Full Circle: The Rise of Vehicle-Installed TelematicsFull Circle: The Rise of Vehicle-Installed Telematics
Full Circle: The Rise of Vehicle-Installed TelematicsHitReach
 
Webinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR Tooling
Webinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR ToolingWebinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR Tooling
Webinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR Tooling
KPIT
 
Megatrends 2013: Manage the Accelerating Amount of Software in Cars
Megatrends 2013: Manage the AcceleratingAmount of Software in CarsMegatrends 2013: Manage the AcceleratingAmount of Software in Cars
Megatrends 2013: Manage the Accelerating Amount of Software in Cars
Red Bend Software
 
automotive emission and control
automotive emission and controlautomotive emission and control
automotive emission and controlLokendra singh
 
Critical Success Factors for A Data Analytics Initiative
Critical Success Factors for A Data Analytics InitiativeCritical Success Factors for A Data Analytics Initiative
Critical Success Factors for A Data Analytics Initiative
Sasken Technologies Ltd.
 
Addressing Security in the Automotive Industry
Addressing Security in the Automotive IndustryAddressing Security in the Automotive Industry
Addressing Security in the Automotive Industry
Sasken Technologies Ltd.
 
M2M Workshop: How FOTA can increase M2M Adoption
M2M Workshop: How FOTA can increase M2M AdoptionM2M Workshop: How FOTA can increase M2M Adoption
M2M Workshop: How FOTA can increase M2M Adoption
Red Bend Software
 
Mapping Automotive SPICE: Achieving Higher Maturity &amp; Capability Levels
Mapping Automotive SPICE: Achieving Higher Maturity &amp; Capability LevelsMapping Automotive SPICE: Achieving Higher Maturity &amp; Capability Levels
Mapping Automotive SPICE: Achieving Higher Maturity &amp; Capability Levels
Luigi Buglione
 
From Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive RevolutionFrom Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive Revolution
Alexander Schellong
 
Bosch: Next Gen Manufacturing and IT
Bosch: Next Gen Manufacturing and ITBosch: Next Gen Manufacturing and IT
Bosch: Next Gen Manufacturing and IT
Rahul Neel Mani
 
The Current State of Automotive Security by Chris Valasek
The Current State of Automotive Security by Chris ValasekThe Current State of Automotive Security by Chris Valasek
The Current State of Automotive Security by Chris Valasek
CODE BLUE
 
Red Bend Software: Optimizing the User Experience with Over-the-Air Updates
Red Bend Software: Optimizing the User Experience with Over-the-Air UpdatesRed Bend Software: Optimizing the User Experience with Over-the-Air Updates
Red Bend Software: Optimizing the User Experience with Over-the-Air Updates
Red Bend Software
 
IoT Seminar (Oct. 2016) Tao Lin - Movimento Group
IoT Seminar (Oct. 2016) Tao Lin - Movimento GroupIoT Seminar (Oct. 2016) Tao Lin - Movimento Group
IoT Seminar (Oct. 2016) Tao Lin - Movimento Group
Open Mobile Alliance
 
Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013
Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013
Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013Arynga
 
[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...
[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...
[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...
CODE BLUE
 
Tesla's technological innovations
Tesla's technological innovationsTesla's technological innovations
Tesla's technological innovations
Ghanesh Kulkarni, PMP
 
IC engines -emission and its control
IC engines -emission and its controlIC engines -emission and its control
IC engines -emission and its control
appu kumar
 
Over-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected carOver-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected car
Pratik Desai, PhD
 

Viewers also liked (20)

20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
 
Automotive security (cvta)
Automotive security (cvta)Automotive security (cvta)
Automotive security (cvta)
 
Full Circle: The Rise of Vehicle-Installed Telematics
Full Circle: The Rise of Vehicle-Installed TelematicsFull Circle: The Rise of Vehicle-Installed Telematics
Full Circle: The Rise of Vehicle-Installed Telematics
 
Webinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR Tooling
Webinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR ToolingWebinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR Tooling
Webinar Presentation- Typical Challenges Faced by Tier 1s in AUTOSAR Tooling
 
Megatrends 2013: Manage the Accelerating Amount of Software in Cars
Megatrends 2013: Manage the AcceleratingAmount of Software in CarsMegatrends 2013: Manage the AcceleratingAmount of Software in Cars
Megatrends 2013: Manage the Accelerating Amount of Software in Cars
 
automotive emission and control
automotive emission and controlautomotive emission and control
automotive emission and control
 
Critical Success Factors for A Data Analytics Initiative
Critical Success Factors for A Data Analytics InitiativeCritical Success Factors for A Data Analytics Initiative
Critical Success Factors for A Data Analytics Initiative
 
Addressing Security in the Automotive Industry
Addressing Security in the Automotive IndustryAddressing Security in the Automotive Industry
Addressing Security in the Automotive Industry
 
M2M Workshop: How FOTA can increase M2M Adoption
M2M Workshop: How FOTA can increase M2M AdoptionM2M Workshop: How FOTA can increase M2M Adoption
M2M Workshop: How FOTA can increase M2M Adoption
 
Mapping Automotive SPICE: Achieving Higher Maturity &amp; Capability Levels
Mapping Automotive SPICE: Achieving Higher Maturity &amp; Capability LevelsMapping Automotive SPICE: Achieving Higher Maturity &amp; Capability Levels
Mapping Automotive SPICE: Achieving Higher Maturity &amp; Capability Levels
 
From Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive RevolutionFrom Connected To Self-Driving - Securing the Automotive Revolution
From Connected To Self-Driving - Securing the Automotive Revolution
 
Bosch: Next Gen Manufacturing and IT
Bosch: Next Gen Manufacturing and ITBosch: Next Gen Manufacturing and IT
Bosch: Next Gen Manufacturing and IT
 
The Current State of Automotive Security by Chris Valasek
The Current State of Automotive Security by Chris ValasekThe Current State of Automotive Security by Chris Valasek
The Current State of Automotive Security by Chris Valasek
 
Red Bend Software: Optimizing the User Experience with Over-the-Air Updates
Red Bend Software: Optimizing the User Experience with Over-the-Air UpdatesRed Bend Software: Optimizing the User Experience with Over-the-Air Updates
Red Bend Software: Optimizing the User Experience with Over-the-Air Updates
 
IoT Seminar (Oct. 2016) Tao Lin - Movimento Group
IoT Seminar (Oct. 2016) Tao Lin - Movimento GroupIoT Seminar (Oct. 2016) Tao Lin - Movimento Group
IoT Seminar (Oct. 2016) Tao Lin - Movimento Group
 
Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013
Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013
Arynga CEO, Walter Buga at Automotive Linux Summit, 5/2013
 
[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...
[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...
[CB16] Using the CGC’s fully automated vulnerability detection tools in secur...
 
Tesla's technological innovations
Tesla's technological innovationsTesla's technological innovations
Tesla's technological innovations
 
IC engines -emission and its control
IC engines -emission and its controlIC engines -emission and its control
IC engines -emission and its control
 
Over-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected carOver-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected car
 

Similar to 20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"

Adaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR Architecture
AdaCore
 
Eliv 2015 bosch-hammel-presentation_v3.4
Eliv 2015 bosch-hammel-presentation_v3.4Eliv 2015 bosch-hammel-presentation_v3.4
Eliv 2015 bosch-hammel-presentation_v3.4
Christof Hammel
 
[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...
[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...
[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...
Obeo
 
Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...
Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...
Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...
BIS Research Inc.
 
FASTR_Overview2017
FASTR_Overview2017FASTR_Overview2017
FASTR_Overview2017Craig Hurst
 
Cav Taguchi autosec china slides
Cav Taguchi autosec china slidesCav Taguchi autosec china slides
Cav Taguchi autosec china slides
Kenji Taguchi
 
Roadshow "Smart production systems @ Valeo 2016-09-15
Roadshow "Smart production systems @ Valeo 2016-09-15Roadshow "Smart production systems @ Valeo 2016-09-15
Roadshow "Smart production systems @ Valeo 2016-09-15
Sirris
 
Managing securityforautomotivesoc
Managing securityforautomotivesocManaging securityforautomotivesoc
Managing securityforautomotivesoc
Pankaj Singh
 
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected VehiclesWebinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
HARMAN Connected Services
 
ConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WPConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WPGreg Harms
 
IDTechEx Research: Printed Electronics for the Automotive Industry
IDTechEx Research: Printed Electronics for the Automotive IndustryIDTechEx Research: Printed Electronics for the Automotive Industry
IDTechEx Research: Printed Electronics for the Automotive Industry
IDTechEx
 
Design reliability 2.0: Safety is Everything
Design reliability 2.0: Safety is Everything Design reliability 2.0: Safety is Everything
Design reliability 2.0: Safety is Everything
Amir Rahat
 
ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019
ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019
ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019
Intland Software GmbH
 
An approach towards sotif with ansys medini analyze
An approach towards sotif with ansys medini analyzeAn approach towards sotif with ansys medini analyze
An approach towards sotif with ansys medini analyze
Bernhard Kaiser
 
Digital Transformation. Examples from Automotive Industry
Digital Transformation. Examples from Automotive IndustryDigital Transformation. Examples from Automotive Industry
Digital Transformation. Examples from Automotive Industry
Boost40
 
Software defined vehicles,automotive standards (safety, security), agile cont...
Software defined vehicles,automotive standards (safety, security), agile cont...Software defined vehicles,automotive standards (safety, security), agile cont...
Software defined vehicles,automotive standards (safety, security), agile cont...
Dr. Anish Cheriyan (PhD)
 
Swiss Re - Insurer Innovation Award 2022
Swiss Re - Insurer Innovation Award 2022Swiss Re - Insurer Innovation Award 2022
Swiss Re - Insurer Innovation Award 2022
The Digital Insurer
 
Security Vision for Software on Wheels (Autonomous Vehicles)
Security Vision for Software on Wheels (Autonomous Vehicles)Security Vision for Software on Wheels (Autonomous Vehicles)
Security Vision for Software on Wheels (Autonomous Vehicles)
Ankit Singh
 
OSS.5 USA Operational, System and Functional Safety for Level 4+ Automation
OSS.5 USA Operational, System and Functional Safety for Level 4+ AutomationOSS.5 USA Operational, System and Functional Safety for Level 4+ Automation
OSS.5 USA Operational, System and Functional Safety for Level 4+ Automation
Maria Willamowius
 
Rail Vision Deck 2022
Rail Vision Deck 2022Rail Vision Deck 2022
Rail Vision Deck 2022
RedChip Companies, Inc.
 

Similar to 20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions" (20)

Adaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR Architecture
 
Eliv 2015 bosch-hammel-presentation_v3.4
Eliv 2015 bosch-hammel-presentation_v3.4Eliv 2015 bosch-hammel-presentation_v3.4
Eliv 2015 bosch-hammel-presentation_v3.4
 
[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...
[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...
[SiriusCon 2020] Pushing Limits in Automotive Model Visualization at BOSCH - ...
 
Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...
Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...
Cybersecurity in Automotive Connected Vehicles and Growing Security Vulnerabi...
 
FASTR_Overview2017
FASTR_Overview2017FASTR_Overview2017
FASTR_Overview2017
 
Cav Taguchi autosec china slides
Cav Taguchi autosec china slidesCav Taguchi autosec china slides
Cav Taguchi autosec china slides
 
Roadshow "Smart production systems @ Valeo 2016-09-15
Roadshow "Smart production systems @ Valeo 2016-09-15Roadshow "Smart production systems @ Valeo 2016-09-15
Roadshow "Smart production systems @ Valeo 2016-09-15
 
Managing securityforautomotivesoc
Managing securityforautomotivesocManaging securityforautomotivesoc
Managing securityforautomotivesoc
 
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected VehiclesWebinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
 
ConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WPConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WP
 
IDTechEx Research: Printed Electronics for the Automotive Industry
IDTechEx Research: Printed Electronics for the Automotive IndustryIDTechEx Research: Printed Electronics for the Automotive Industry
IDTechEx Research: Printed Electronics for the Automotive Industry
 
Design reliability 2.0: Safety is Everything
Design reliability 2.0: Safety is Everything Design reliability 2.0: Safety is Everything
Design reliability 2.0: Safety is Everything
 
ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019
ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019
ALM for Developing Engineered Systems - Michael Azoff (Ovum) - 14 May 2019
 
An approach towards sotif with ansys medini analyze
An approach towards sotif with ansys medini analyzeAn approach towards sotif with ansys medini analyze
An approach towards sotif with ansys medini analyze
 
Digital Transformation. Examples from Automotive Industry
Digital Transformation. Examples from Automotive IndustryDigital Transformation. Examples from Automotive Industry
Digital Transformation. Examples from Automotive Industry
 
Software defined vehicles,automotive standards (safety, security), agile cont...
Software defined vehicles,automotive standards (safety, security), agile cont...Software defined vehicles,automotive standards (safety, security), agile cont...
Software defined vehicles,automotive standards (safety, security), agile cont...
 
Swiss Re - Insurer Innovation Award 2022
Swiss Re - Insurer Innovation Award 2022Swiss Re - Insurer Innovation Award 2022
Swiss Re - Insurer Innovation Award 2022
 
Security Vision for Software on Wheels (Autonomous Vehicles)
Security Vision for Software on Wheels (Autonomous Vehicles)Security Vision for Software on Wheels (Autonomous Vehicles)
Security Vision for Software on Wheels (Autonomous Vehicles)
 
OSS.5 USA Operational, System and Functional Safety for Level 4+ Automation
OSS.5 USA Operational, System and Functional Safety for Level 4+ AutomationOSS.5 USA Operational, System and Functional Safety for Level 4+ Automation
OSS.5 USA Operational, System and Functional Safety for Level 4+ Automation
 
Rail Vision Deck 2022
Rail Vision Deck 2022Rail Vision Deck 2022
Rail Vision Deck 2022
 

Recently uploaded

gtyccccccccccccccccccccccccccccccccccccccccccccccccccccccc
gtycccccccccccccccccccccccccccccccccccccccccccccccccccccccgtyccccccccccccccccccccccccccccccccccccccccccccccccccccccc
gtyccccccccccccccccccccccccccccccccccccccccccccccccccccccc
4thzenzstar
 
Wondering if Your Mercedes EIS is at Fault Here’s How to Tell
Wondering if Your Mercedes EIS is at Fault Here’s How to TellWondering if Your Mercedes EIS is at Fault Here’s How to Tell
Wondering if Your Mercedes EIS is at Fault Here’s How to Tell
Vic Auto Collision & Repair
 
What Does the Active Steering Malfunction Warning Mean for Your BMW
What Does the Active Steering Malfunction Warning Mean for Your BMWWhat Does the Active Steering Malfunction Warning Mean for Your BMW
What Does the Active Steering Malfunction Warning Mean for Your BMW
Tanner Motors
 
一比一原版BC毕业证波士顿学院毕业证成绩单如何办理
一比一原版BC毕业证波士顿学院毕业证成绩单如何办理一比一原版BC毕业证波士顿学院毕业证成绩单如何办理
一比一原版BC毕业证波士顿学院毕业证成绩单如何办理
amvovau
 
Antique Plastic Traders Company Profile
Antique Plastic Traders Company ProfileAntique Plastic Traders Company Profile
Antique Plastic Traders Company Profile
Antique Plastic Traders
 
Ec460b lc Excavator Volvo Service Repair.pdf
Ec460b lc Excavator Volvo Service Repair.pdfEc460b lc Excavator Volvo Service Repair.pdf
Ec460b lc Excavator Volvo Service Repair.pdf
Excavator
 
Empowering Limpopo Entrepreneurs Consulting SMEs.pptx
Empowering Limpopo Entrepreneurs  Consulting SMEs.pptxEmpowering Limpopo Entrepreneurs  Consulting SMEs.pptx
Empowering Limpopo Entrepreneurs Consulting SMEs.pptx
Precious Mvulane CA (SA),RA
 
Things to remember while upgrading the brakes of your car
Things to remember while upgrading the brakes of your carThings to remember while upgrading the brakes of your car
Things to remember while upgrading the brakes of your car
jennifermiller8137
 
What Exactly Is The Common Rail Direct Injection System & How Does It Work
What Exactly Is The Common Rail Direct Injection System & How Does It WorkWhat Exactly Is The Common Rail Direct Injection System & How Does It Work
What Exactly Is The Common Rail Direct Injection System & How Does It Work
Motor Cars International
 
Ec330B Lc Excavator Volvo Service Repair.pdf
Ec330B Lc Excavator Volvo Service Repair.pdfEc330B Lc Excavator Volvo Service Repair.pdf
Ec330B Lc Excavator Volvo Service Repair.pdf
Excavator
 
Tyre Industrymarket overview with examples of CEAT
Tyre Industrymarket overview with examples of CEATTyre Industrymarket overview with examples of CEAT
Tyre Industrymarket overview with examples of CEAT
kshamashah95
 
Statistics5,c.xz,c.;c.;d.c;d;ssssss.pptx
Statistics5,c.xz,c.;c.;d.c;d;ssssss.pptxStatistics5,c.xz,c.;c.;d.c;d;ssssss.pptx
Statistics5,c.xz,c.;c.;d.c;d;ssssss.pptx
coc7987515756
 
Core technology of Hyundai Motor Group's EV platform 'E-GMP'
Core technology of Hyundai Motor Group's EV platform 'E-GMP'Core technology of Hyundai Motor Group's EV platform 'E-GMP'
Core technology of Hyundai Motor Group's EV platform 'E-GMP'
Hyundai Motor Group
 
一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理
一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理
一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理
psavhef
 
Why Isn't Your BMW X5's Comfort Access Functioning Properly Find Out Here
Why Isn't Your BMW X5's Comfort Access Functioning Properly Find Out HereWhy Isn't Your BMW X5's Comfort Access Functioning Properly Find Out Here
Why Isn't Your BMW X5's Comfort Access Functioning Properly Find Out Here
Masters European & Gapanese Auto Repair
 
Why Is Your BMW X3 Hood Not Responding To Release Commands
Why Is Your BMW X3 Hood Not Responding To Release CommandsWhy Is Your BMW X3 Hood Not Responding To Release Commands
Why Is Your BMW X3 Hood Not Responding To Release Commands
Dart Auto
 
What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...
What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...
What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...
Autohaus Service and Sales
 
5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention
5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention
5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention
Bertini's German Motors
 
What Causes 'Trans Failsafe Prog' to Trigger in BMW X5
What Causes 'Trans Failsafe Prog' to Trigger in BMW X5What Causes 'Trans Failsafe Prog' to Trigger in BMW X5
What Causes 'Trans Failsafe Prog' to Trigger in BMW X5
European Service Center
 

Recently uploaded (19)

gtyccccccccccccccccccccccccccccccccccccccccccccccccccccccc
gtycccccccccccccccccccccccccccccccccccccccccccccccccccccccgtyccccccccccccccccccccccccccccccccccccccccccccccccccccccc
gtyccccccccccccccccccccccccccccccccccccccccccccccccccccccc
 
Wondering if Your Mercedes EIS is at Fault Here’s How to Tell
Wondering if Your Mercedes EIS is at Fault Here’s How to TellWondering if Your Mercedes EIS is at Fault Here’s How to Tell
Wondering if Your Mercedes EIS is at Fault Here’s How to Tell
 
What Does the Active Steering Malfunction Warning Mean for Your BMW
What Does the Active Steering Malfunction Warning Mean for Your BMWWhat Does the Active Steering Malfunction Warning Mean for Your BMW
What Does the Active Steering Malfunction Warning Mean for Your BMW
 
一比一原版BC毕业证波士顿学院毕业证成绩单如何办理
一比一原版BC毕业证波士顿学院毕业证成绩单如何办理一比一原版BC毕业证波士顿学院毕业证成绩单如何办理
一比一原版BC毕业证波士顿学院毕业证成绩单如何办理
 
Antique Plastic Traders Company Profile
Antique Plastic Traders Company ProfileAntique Plastic Traders Company Profile
Antique Plastic Traders Company Profile
 
Ec460b lc Excavator Volvo Service Repair.pdf
Ec460b lc Excavator Volvo Service Repair.pdfEc460b lc Excavator Volvo Service Repair.pdf
Ec460b lc Excavator Volvo Service Repair.pdf
 
Empowering Limpopo Entrepreneurs Consulting SMEs.pptx
Empowering Limpopo Entrepreneurs  Consulting SMEs.pptxEmpowering Limpopo Entrepreneurs  Consulting SMEs.pptx
Empowering Limpopo Entrepreneurs Consulting SMEs.pptx
 
Things to remember while upgrading the brakes of your car
Things to remember while upgrading the brakes of your carThings to remember while upgrading the brakes of your car
Things to remember while upgrading the brakes of your car
 
What Exactly Is The Common Rail Direct Injection System & How Does It Work
What Exactly Is The Common Rail Direct Injection System & How Does It WorkWhat Exactly Is The Common Rail Direct Injection System & How Does It Work
What Exactly Is The Common Rail Direct Injection System & How Does It Work
 
Ec330B Lc Excavator Volvo Service Repair.pdf
Ec330B Lc Excavator Volvo Service Repair.pdfEc330B Lc Excavator Volvo Service Repair.pdf
Ec330B Lc Excavator Volvo Service Repair.pdf
 
Tyre Industrymarket overview with examples of CEAT
Tyre Industrymarket overview with examples of CEATTyre Industrymarket overview with examples of CEAT
Tyre Industrymarket overview with examples of CEAT
 
Statistics5,c.xz,c.;c.;d.c;d;ssssss.pptx
Statistics5,c.xz,c.;c.;d.c;d;ssssss.pptxStatistics5,c.xz,c.;c.;d.c;d;ssssss.pptx
Statistics5,c.xz,c.;c.;d.c;d;ssssss.pptx
 
Core technology of Hyundai Motor Group's EV platform 'E-GMP'
Core technology of Hyundai Motor Group's EV platform 'E-GMP'Core technology of Hyundai Motor Group's EV platform 'E-GMP'
Core technology of Hyundai Motor Group's EV platform 'E-GMP'
 
一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理
一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理
一比一原版SDSU毕业证圣地亚哥州立大学毕业证成绩单如何办理
 
Why Isn't Your BMW X5's Comfort Access Functioning Properly Find Out Here
Why Isn't Your BMW X5's Comfort Access Functioning Properly Find Out HereWhy Isn't Your BMW X5's Comfort Access Functioning Properly Find Out Here
Why Isn't Your BMW X5's Comfort Access Functioning Properly Find Out Here
 
Why Is Your BMW X3 Hood Not Responding To Release Commands
Why Is Your BMW X3 Hood Not Responding To Release CommandsWhy Is Your BMW X3 Hood Not Responding To Release Commands
Why Is Your BMW X3 Hood Not Responding To Release Commands
 
What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...
What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...
What Does the PARKTRONIC Inoperative, See Owner's Manual Message Mean for You...
 
5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention
5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention
5 Warning Signs Your BMW's Intelligent Battery Sensor Needs Attention
 
What Causes 'Trans Failsafe Prog' to Trigger in BMW X5
What Causes 'Trans Failsafe Prog' to Trigger in BMW X5What Causes 'Trans Failsafe Prog' to Trigger in BMW X5
What Causes 'Trans Failsafe Prog' to Trigger in BMW X5
 

20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"

  • 1. Automotive Security: Challenges, Standards and Solutions Alexander Much 2016-09-14 CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
  • 2. Automotive Security: Challenges, Standards and Solutions Agenda 2 • Safety, Security, ? • Related Standards and Activities • Solutions • Summary CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
  • 3. Automotive Security: Challenges, Standards and Solutions Driver´s fears are being fueled by recent news • a 3 Connected Cars (new opportunities for hackers) New Autonomous Driving Concepts (and failures) CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Opposing Goals?
  • 4. Automotive Security: Challenges, Standards and Solutions Connected Car offers new business models for hackers? • a 4CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
  • 5. Automotive Security: Challenges, Standards and Solutions Autonomous theft? 55CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
  • 6. Automotive Security: Challenges, Standards and Solutions ;-) 6 © xkcd.com, https://xkcd.com/1559/ CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
  • 7. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions “Trustworthy Computing” Memo From: Bill Gates Sent: Tuesday, January 15, 2002 5:22 PM To: Microsoft and Subsidiaries: All FTE Subject: Trustworthy computing When we face a choice between adding features and resolving security issues, we need to choose security. We must lead the industry to a whole new level of Trustworthiness in computing. […] Trustworthy Computing is the highest priority for all the work we are doing. […] Key aspects include: […] Availability, […] Security, […] Privacy. Do we have similar challenges? 7
  • 8. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions The Evolution of Car Hacking 88 Increasing digitalization and digital integration Hypothetical vulnerabilities identified Regular security breaches with severe damages Security threats become relevant in practice Security Issues Source: escrypt
  • 9. Automotive Security: Challenges, Standards and Solutions Dependability 9 Important: • safety != reliability • safety != security • safety != availability The challenge: balancing „ilities“. Safety << Security! Must-read paper: „Basic Concepts and Taxonomy of Dependable and Secure Computing“ https://www.nasa.gov/pdf/636745main_day_3- algirdas_avizienis.pdf Also look at: Architecture Tradeoff Method, SEI: https://resources.sei.cmu.edu/asset_files/TechnicalRepo rt/2000_005_001_13706.pdf Dependability Attributes Security Availability Reliability Safety Integrity Maintainability Threats Fault Error Failure Means Prevention Removal Forecasting Tolerance Documentation https://en.wikipedia.org/wiki/Dependability CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
  • 10. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Entry Points 10 Internet connection Bluetooth connection Wireless key Tire pressure monitor Remote start Remote HVAC WiFi Hotspot Car2Infrastructure Car2Car eCall
  • 11. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Excursion: Legal Key quotes for security from 53. Goslaer Verkehrsgerichtstag, 2015-01: „Zur Klärung von Haftungsansprüchen nach Schadensfällen in jeglichem automatisierten Fahrbetrieb müssen Systemhandlungen und Eingriffe des Fahrers beweissicher (!) dokumentiert werden.“  tamper-resistant black-box (individual ECUs, function and system level) „Datenschutz und Datensicherheit sowie Transparenz für den Nutzer sind dabei zu gewährleisten.“ „Gegen Manipulationen von außen ist entsprechend dem Stand der Technik Vorsorge zu treffen.“  tamper-resistant devices and communication, authenticity, privacy, etc. On the horizon: the US may mandate such requirements. 11
  • 12. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Related Standards and Activities • NIST, FIPS, etc. • CERT (coding standards and more) • ISO 27000 (wikipedia) • RTCA/DO-326 (avionics) • IEC 62443 (primarily automation) • CMMI (Security by Design with CMMI v1.3, from Siemens) • Microsoft SDL (Security Development Lifecycle) • EVITA (research project) • BMW group standard (GS 95014, 2015-02) • SAE J3061 (to be published on 2015-12-03) • OpenSAMM (Software Assurance Maturity Model) (4 additional processes, similar to e.g. ISO 15504-10 • … and probably many more 12
  • 13. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Excerpt from J3061 activities • Tailors a security process framework from the ISO 26262 process framework  Compatibility of the lifecycle and processes • Goal-based rather than predictive • Identifies methods and tools to facilitate the application of the process, e.g. ‒ Attack trees ‒ Penetration testing ‒ TARA methods (Thread And Risk Analysis) • Published on 2015-12-03 with a webcast: “The World’s First Standard on Automotive Cybersecurity.” 13
  • 14. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Safety & Security: Process Model Coordination needed between safety and security experts in relevant phases. Key capability: systems engineering. Safety & Security are system aspects (“emerging properties”, “speciality engineering”). 14 © Bosch, S. Kriso, M. Ihle, „Automotive Security im Kontext der Funktionalen Sicherheit“, VDI / VW Gemeinschaftstagung „Automotive Security“, 2015-10-21
  • 15. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions The “System” Defining the system boundaries is complex in development as well as during operations. Systems are dynamic: assumptions made during development may be false during operations. 15 © Nancy Leveson, Engineering a Safer World (free download)
  • 16. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Extension of the Life-Cycle • Automotive SPICE strongly focuses on development. • ISO 15504:2006 contains OPE.1 – Operational use, 5 base practices. IMHO: rarely used. • ISO 26262:2011 part 7 chapter 6: “operation, service and decommissioning”. 3 pages, fairly abstract. • Security needs constant field monitoring of all stakeholders: ‒ Safety: a “static” hazard model ‒ Security: a “dynamic” threat model • Security leads to a higher frequency of updates:  maintainability, changeability is a key factor • Incidents will happen => security is only mastered with a plan for response! 16
  • 17. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions OTA & Quality: A “Warning” • OTA offers many opportunities, including business models, etc. • OTA will fundamentally change how we look at function deployment. • OTA partially lowers SOP “pressure”: “we’ll add / fix it later” • Easy updates have lead to crappy software in other domains. • The SPICE community needs to be aware of this fact! 17
  • 18. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Example: Microsoft SDL • Core Security Training • Establish Security and Privacy Requirements • Create Quality Gates / Bug Bars • Perform Security and Privacy Risk Assessments • Establish Design Requirements • Attack Surface Analysis / Reduction • Use Threat Modeling • Use Approved Tools 18 • Deprecate Unsafe Functions • Perform Static Analysis • Perform Dynamic Analysis • Fuzz Testing • Attack Surface Review • Create an Incident Response Plan • Conduct Final Security Review • Certify Release and Archive • Execute Incident Response Plan
  • 19. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Example: OpenSAMM 19
  • 20. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Example: SAE J3061 20 Potential Communications Paths During the Product Development (software level) Activities
  • 21. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Secure System Layers 21 Secure Environment Secure External Comm. & Interfaces Secure Network Segmentation Secure OnBoard Communication Secure Platform Secure Boot Secure Hardware Element Secure Update / Diagnostics - Applications - Flashware Separation / Isolation - Memory Protection - Scheduling Policies - Access Control AUTOSAR SecOC Ethernet Security Domain Separation Trust Zones IDS/ADS Firewall Secure External Channels - TLS Secure Logging Agent Secure Backend Infrastructure
  • 22. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Possible Solutions (from Os side) 22 Core PartitioningPure Autosar Hypervisor App App Core 1 ECU Core 2 AUTOSAR Performance Platform App App Core 1 ECU Core 2 AUTOSAR Performance Platform App App Core 1 ECU Core 2 AUTOSAR Hypervisor Performance Platform App App Core 1 ECU Core 2 Microcontroller Partitioning Performance Platform App App Micro 1 ECU Micro 2 AUTOSAR Pure Performance
  • 23. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Reference Architecture for Safe & Secure Platform 23 OS (opt.) Bootloader / Flasher ECUECU Ethernet, FlexRay, CAN, LIN OS RTE Applications AUTOSAR Hardware Hardware Security Module (HSM) CSM CryHSM SecOC Application Bootloader/Flasher Authentication SW signature verification Anti theft SW as a product Milage prot. Secure Boot Intrusion Det. EB Software
  • 24. CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Automotive Security: Challenges, Standards and Solutions Summary (and opinion) Processes & standards: Standardization for security similar to ISO 26262 is needed, which forms a consensus in the automotive domain. Safety, security, reliability are system aspects that need to be balanced.  They are all part of the “quality” of the product. We need assessors who are technical experts of the systems they assess.  “Simple” process and document checking won’t be enough. The SPICE community needs to co-ordinate specialty engineering audits. Systems engineering needs to be established within organizations. 24
  • 25. Contact us! automotive.elektrobit.com alexander.much@elektrobit.com CC SSE Much | 2016-09-14 | EuroAsiaSPI 2016 | Public | © Elektrobit Automotive GmbH 2016. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.