The Security Aspects of Automotive Over-the-Air Updates

The Security Aspects of Automotive Over-the-Air Updates

James Howden, Leandros Maglaras, Mohamed Amine Ferrag
Copyright: © 2020 |Pages: 18
DOI: 10.4018/IJCWT.2020040104
OnDemand:
(Individual Articles)
Available
$37.50
No Current Special Offers
TOTAL SAVINGS: $37.50

Abstract

Over-the-air (OTA) update is a method for vehicle manufacturers to remotely distribute maintenance updates, performance, and feature enhancements through the vehicle's lifespan. Recalls of vehicles cost the manufactures a lot of money. OTA solves the recall issue, while allowing consumers to pay for services and features via an update. The OTA ecosystem includes the coders who first developed the firmware, the 1st Tier suppliers, the vehicle manufacturers, and the vehicle itself. Currently, manufacturers designed the networks for speed and responsiveness, and not security. This article examines these elements and drills into the security available for each. The slowest and one of the most vulnerable parts of the system is the communications within the vehicle. The vehicle networks must ensure the integrity and authenticity of messages transmitted to guarantee software programmed onto ECUs are authorized and tamper-free. Specialist hardware within the vehicle makes this possible in an operation environment, such as hardware security modules.
Article Preview
Top

Recently several scholars have researched the area of security issues of smart cars (Maglaras, 2015) and especially those related to OTA. An OTA update system must be resilient to spoofing, tampering, repudiation, information-leakage, denial-of-service, and escalation-of-privileges attacks among others (Vasenev, 2019). Several security and privacy issues may arise from different parts of the ecosystem, like cloud, Service station, car or OEM backend and several security methods must be combined in order to counter those threats. The freshness of the update information also needs to be preserved in order to prevent replay attacks (Halder, 2019). Moreover, software distribution during OTA updates must be arranged in such a way that high security; low latency and continuous data protection are guaranteed.

Complete Article List

Search this Journal:
Reset
Volume 14: 1 Issue (2024)
Volume 13: 1 Issue (2023)
Volume 12: 4 Issues (2022): 2 Released, 2 Forthcoming
Volume 11: 4 Issues (2021)
Volume 10: 4 Issues (2020)
Volume 9: 4 Issues (2019)
Volume 8: 4 Issues (2018)
Volume 7: 4 Issues (2017)
Volume 6: 4 Issues (2016)
Volume 5: 4 Issues (2015)
Volume 4: 4 Issues (2014)
Volume 3: 4 Issues (2013)
Volume 2: 4 Issues (2012)
Volume 1: 4 Issues (2011)
View Complete Journal Contents Listing