OTA and Remote Diagnostics

Similar documents
Securing the future of mobility

PREEvision Technical Article

SW-Update. Thomas Fleischmann June 5 th 2015

Diagnostic Use Cases V

Diagnostics is evolving

10 th AUTOSAR Open Conference

The Adaptive Platform for Future Use Cases

Flash Bootloader. Product Information

Standardized Tool Components for NRMM-Diagnostics

Adaptive AUTOSAR. Ready for Next Generation ECUs V

Diagnostic Trends 2017 An Overview

Sicherheitsaspekte für Flashing Over The Air in Fahrzeugen. Axel Freiwald 1/2017

TechPaper. Over-the-air updates what advantages does the AUTOSAR Adaptive Platform offer?

10 th AUTOSAR Open Conference

Automotive Anomaly Monitors and Threat Analysis in the Cloud

Cyber security mechanisms for connected vehicles

AUTOSAR proofs to be THE automotive software platform for intelligent mobility

vflash Vector Webinar V

Efficient testing of ECUs despite Security

Automotive Security: Challenges and Solutions

SIMPLIFYING THE CAR. Helix chassis. Helix chassis. Helix chassis WIND RIVER HELIX CHASSIS WIND RIVER HELIX DRIVE WIND RIVER HELIX CARSYNC

Indigo. Vector Diagnostic Tester V / 6

Adaptive AUTOSAR Extending the Scope of AUTOSAR-based Embedded Software

A NEW CONCEPT IN OTA UPDATING FOR AUTOMOTIVE

Automotive Gateway: A Key Component to Securing the Connected Car

The modern car has 100 million lines of code and over half of new vehicles will be connected by 2020.

Secure Ethernet Communication for Autonomous Driving. Jared Combs June 2016

Adaptive AUTOSAR Extending the Scope of AUTOSAR-based Embedded Software

OFF-ROAD VEHICLE DIAGNOSTICS WITH AUTOSAR. Jigar Patel Namdeo Dhawle July 18, 2018

The CANoe.Ethernet Solution

CAN FD - Flexible Tools for Flexible Data Rates

Ideation for Telematics, Highly Automated Driving Armin Rupalla

Vector Logger Cloud. VECTOR GB Ltd Conference, 28th Sept, 2017 V

Realizing Automated Driving Systems using Ethernet TSN and Adaptive AUTOSAR

M2MD Communications Gateway: fast, secure, efficient

High-Speed Reprogramming and Calibration with CAN FD: A Case Study

Securing the Connected Car. Eystein Stenberg CTO Mender.io

Securing the Connected Car. Eystein Stenberg Product Manager Mender.io

10 th AUTOSAR Open Conference

Countermeasures against Cyber-attacks

The case for a Vehicle Gateway.

Building Digital Key Solution for Automotive

Open Source in Automotive Infotainment

Automotive Security An Overview of Standardization in AUTOSAR

PENETRATION TESTING OF AUTOMOTIVE DEVICES. Dr. Ákos Csilling Robert Bosch Kft., Budapest HUSTEF 15/11/2017

How Security Mechanisms Can Protect Cars Against Hackers. Christoph Dietachmayr, CIS Solution Manager EB USA Techday, Dec.

November 16, TTTech Computertechnik AG / TTTech Auto AG Copyright TTTech Auto AG. All rights reserved

Introducing Hardware Security Modules to Embedded Systems

Connected Car Solutions Based on IoT

Connected driving is the future. However, data exchange between vehicles. and roadside equipment will only become genuinely beneficial when it is

ODX-LINK V1.5 ODX-FLASH V1.5 User s Guide

CANoe.J1939. Product Information

Designing a software framework for automated driving. Dr.-Ing. Sebastian Ohl, 2017 October 12 th

Development of Intrusion Detection System for vehicle CAN bus cyber security

CAN FD with Dynamic Multi-PDU-to-Frame Mapping

AWS Connected Vehicle Cloud

Fending Off Cyber Attacks Hardening ECUs by Fuzz Testing

time now it has also been used productively in a multi-oem, requires precise knowledge of the protocol, the layout, the

Automotive Security: Challenges, Standards and Solutions. Alexander Much 12 October 2017

Autonomous Driving From Fail-Safe to Fail-Operational Systems

Trusted Platform Modules Automotive applications and differentiation from HSM

M2MD Communications Gateway: fast, secure and efficient

CANoe.Ethernet. Product Information

13W-AutoSPIN Automotive Cybersecurity

Trusted Platform for Mobile Devices: Challenges and Solutions

10 th AUTOSAR Open Conference

Current status and Future of AUTOSAR. Markus Bechter 7 th AUTOSAR Open Conference Oct. 22 nd -23 rd 2014, Detroit

Secure Product Design Lifecycle for Connected Vehicles

ASAM MCD-3 D. Application Programming Interface for MVCI Diagnostic Server. Base Standard. Part 1 of 4. Version 3.0.

Internet of things (IoT)

10 th AUTOSAR Open Conference

Building firmware update: The devil is in the details

Connected vehicle cloud

The Bosch IoT Remote Manager

ITEC 350: Introduction To Computer Networking Midterm Exam #2 Key. Fall 2008

SECURITY STORY WE NEVER SEE, TOUCH NOR HOLD YOUR DATA

Driven by SOLUTIONS. The new generation of vehicle diagnostic solutions. ESI[tronic], KTS and DCU from Bosch

Market Trends and Challenges in Vehicle Security

STW s Connectivity Solution for Mobile Equipment: The Vehicle Data System (VDS) and VDS-Remote (VDS-R) 31 July 2009, STW, Norcross, Bob Geiger

Extreme automation of today s technological marvel - connected cars

Preventing External Connected Devices From Compromising Vehicle Systems Vector Congress November 7, 2017 Novi, MI

Cyber Security and Vehicle Diagnostics. Mark Zachos DG Technologies

Context-aware Automotive Intrusion Detection

Using a Certified Hypervisor to Secure V2X communication

The Information Age has brought enormous

.NET Secure Coding for Client-Server Applications 4-Day hands on Course. Course Syllabus

Examining future priorities for cyber security management

Firmware Updates for Internet of Things Devices

Safety and Security for Automotive using Microkernel Technology

Scalable and Flexible Software Platforms for High-Performance ECUs. Christoph Dietachmayr Sr. Engineering Manager, Elektrobit November 8, 2018

Software Architecture. Definition of Software Architecture. The importance of software architecture. Contents of a good architectural model

Linux and AUTOSAR Vector Informatik Congress, Stuttgart,

Architecture concepts in Body Control Modules

Agenda. About TRL. What is the issue? Security Analysis. Consequences of a Cyber attack. Concluding remarks. Page 2

CANalyzer.J1939. Product Information

Driven by SOLUTIONS. Professional vehicle diagnostic solutions for every workshop. ESI[tronic] 2.0 Online - KTS - DCU

Internet of secure things: issues and perspectives. Pasquale Pace Dimes - UNICAL

Using the Cisco ACE Application Control Engine Application Switches with the Cisco ACE XML Gateway

EB TechPaper. Combining the strengths of Elektrobit's SecOC with Argus IDPS. elektrobit.com

Arccore AB 2017, all rights reserved. Accelerating innovation

Transcription:

OTA and Remote Diagnostics Vector ongress 26, Stuttgart, 26--29 V. 26--29

onnectivity offers greater Benefit to the automotive industry At a glance onnectivity offers greater benefit to the Automotive Industry: Software update Remote diagnostics Data collection There is a need for prompt delivery of OTA We have identified the most important success factors: Security Reliability Reuse A successful implementation requires significant know how in automotive and IT 2/8

onnectivity offers greater benefit to the Automotive Industry Software update adds value and is a way to keep connectivity secure lassic AUTOSAR and others: Reprogramming monolithic blocks with UDS protocol. Adaptive AUTOSAR and POSIX-like operating systems: Install and update software packages onsider dependencies between programs and shared libraries. Updating connectivity and OTA: Maintain the communication and security relevant parts of the vehicle There is a risk for brain dead vehicles (no communication) lassic Adaptive 3/8

onnectivity offers greater benefit to the Automotive Industry Remote diagnostics adds disruptive elements to well-known applications ompile and send regular vehicle health-reports Summarize present and stored failures, gas consumption, mileage, oil-level, Useful information for the driver Useful information for the OEM: Get deep insight into fleet health status Get remote roadside assistance from central vehicle support centers Allows remote diagnostics when malfunction indicator illuminates: ontinue drive or keep waiting for the towing service? Some EE issues can even be solved immediately. Make inspection and repair in car workshop more predictable and comfortable Actions, effort, time of visit can be planned beforehand based on vehicle health-report and an enhanced remote diagnostics when required Spare parts will be ordered early and are already available when car comes in 4/8

onnectivity offers greater benefit to the Automotive Industry Data ollection provides new insights into vehicles in the field Setup a campaign to analyze a certain phenomenon Select vehicles Define measurement configuration and trigger condition Transfer configuration from backend into vehicles of selected fleet Perform measurement, pre-evaluate and collect data Transfer data to the backend Perform data analytics Refine configuration if needed lose campaign Internet Backend 5/8

There is a Need for prompt Delivery of OTA There is a need for prompt delivery of OTA The starting signal has been given First applications are already available. Some customers do expect such functions. http://de.freepik.com/fotos-vektoren-kostenlos/menschen Menschen vektor durch Kjpargeter Freepik.com entwickelt 6/8

We have identified the most important success Factors We have identified the most important success factors Security Establish a secure channel that guarantees privacy and authentication. Reliability Make OTA functions robust and efficient. Reuse Take advantage of well-proven industry standards. Integrate into existing processes. Benefits Provide convenient functionality with additional value for the car owner 7/8

We have identified the most important success factors Security - A threat analysis on the OTA process PDX Backend Internet onnectivity Diag gateway Assets Flash data along the communication path: > Over-the-air communication between backend and vehicle. > Storage devices. > In-vehicle communication. Body hassis Gateway Security keys of the devices. Threats: > ompromising keys. > Data access or manipulation. > Man-in-the-middle. > Denial of services. Impacts: > Financial loss. > Manufacturer reputation. > System malfunction. > Safety functions. Flash Bootloader ADAS Infotainment 8/8

We have identified the most important success factors Security - A threat analysis on the OTA process PDX Backend Internet onnectivity Diag gateway Assets Flash data along the communication path: > Over-the-air communication Protect between the backend data on and storage vehicle. devices from > Storage devices. reading and writing by malicious attacker. > In-vehicle communication. Body hassis Gateway Security keys of the devices. Threats: > ompromising keys. > Data access or manipulation. > Man-in-the-middle. > Denial of services. Impacts: > Financial loss. > Manufacturer reputation. > System malfunction. > Safety functions. Flash Bootloader ADAS Infotainment 9/8

We have identified the most important success factors Security - A threat analysis on the OTA process PDX Backend Internet onnectivity Diag gateway Assets Flash data along the communication Separating path: the connectivity module in the > Over-the-air communication architecture between backend provides and vehicle. less attack surface. > Storage devices. Even if hacked, there is no direct access to > In-vehicle communication. vehicle buses. Body hassis Gateway Security keys of the devices. Threats: > ompromising keys. > Data access or manipulation. > Man-in-the-middle. > Denial of services. Impacts: > Financial loss. > Manufacturer reputation. > System malfunction. > Safety functions. Flash Bootloader ADAS Infotainment /8

We have identified the most important success factors Security - A threat analysis on the OTA process PDX Backend Internet onnectivity Diag gateway Assets Flash data along the communication Over-the-air path: communication uses PKI and > Over-the-air communication certificate between backend handling. vehicle. > Storage devices. The connectivity device handles and stores > In-vehicle communication. the key material. Body hassis Gateway Security keys of the devices. Threats: > ompromising keys. > Data access or manipulation. > Man-in-the-middle. > Denial of services. Impacts: > Financial loss. > Manufacturer reputation. > System malfunction. > Safety functions. Flash Bootloader ADAS Infotainment /8

We have identified the most important success factors Security - A threat analysis on the OTA process PDX Backend Internet onnectivity Diag gateway Assets Flash data along the communication path: End-to-end protection with digital signatures. > Over-the-air communication between backend and vehicle. > Storage devices. Additionally, data can be encrypted and decrypted inside the bootloader. > In-vehicle communication. Body hassis Gateway Security keys of the devices. Threats: > ompromising keys. > Data access or manipulation. > Man-in-the-middle. > Denial of services. Impacts: > Financial loss. > Manufacturer reputation. > System malfunction. > Safety functions. Flash Bootloader ADAS Infotainment 2/8

We have identified the most important success factors Reliability - Software update with redundant data storage Keep current and new version in the EU: onnectivity EU Software download is performed into the secondary memory section. Application V. Application V2. In case of a failure, all EUs will keep on executing the current version. Data V2. Diag gateway Ready for execution UDS- Flash Bootloader Programming Keep current and new version at central location: onnectivity EU In case of a failure, the update can be rolled back. Data V. Diag gateway Application V2. Programming Data V2. UDS- Flash Bootloader 3/8

We have identified the most important success factors Reuse: Take advantage of existing protocols - what do we need? There are many existing protocols. The best choice depends on the use case: Synchronous or asynchronous, client/server or peer-to-peer, streaming or event triggered. Which one is the best for given use-cases in the automotive industry? Data collection Software Update Remote Diagnostics App A App B App DoIP SOME/IP OMA-DM SOAP HTTP(S) MQTT BEEP SMTP (S)FTP UDS OBD UDP TP/TLS SOAP {REST} 4/8

We have identified the most important success factors Reuse: Onboard - Offboard Responsibilities Abstraction Layer Backend proprietary Tester Application MVI-Server JOBs ODX*/ PDX* 2 Where to cut between vehicle and backend on communication or on a more abstract level? Keep and manage data containers required for interpretation in the backend or the car? Or break down containers? Vehicle D-PDU-API 3 Autosar * Typically proprietary binary runtime format on the abstraction layer of the standard. 5/8

A successful implementation requires significant know how in automotive and IT A successful implementation requires significant know how in automotive and IT A sustainable solution integrates in-vehicle and backend/server software seamlessly. 6/8

onnectivity offers greater Benefit to the automotive industry Summary onnectivity offers greater benefit to the Automotive Industry: Software update Remote diagnostics Data collection There is a need for prompt delivery of OTA We have identified the most important success factors: Security Reliability Reuse A successful implementation requires significant know how in automotive and IT Vector is familiar with Automotive and IT. 7/8

For more information about Vector and our products please visit www.vector.com Author: Volker Ebner, Armin Happel, hristoph Rätz Vector Germany 26. Vector Informatik GmbH. All rights reserved. Any distribution or copying is subject to prior written approval by Vector. V. 26--29