> Markdown version of [/videos/572-automotive-security-challenges-a-supplier-s-view?t=1958](https://www.wearedevelopers.com/videos/572-automotive-security-challenges-a-supplier-s-view?t=1958). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Automotive Security Challenges: A Supplier's View Attackers are disguising CAN bus exploits as emergency jump-starters to compromise software-defined vehicles. Discover how suppliers secure modern fleets against ransomware without sacrificing strict millisecond latency requirements. - **Speakers:** Davor Frkat - **Event:** WeAreDevelopers LIVE - **Published:** April 27, 2023 - **Duration:** 58:59 - **URL:** https://www.wearedevelopers.com/videos/572-automotive-security-challenges-a-supplier-s-view ## Summary The transition of modern vehicles from offline mechanical hardware to highly connected, software-defined systems has exponentially expanded the automotive attack surface. As a Tier-1 supplier, Bosch Engineering approaches these vulnerabilities holistically—from pre-development architecture and concept consulting to post-production incident response and the implementation of Vehicle Security Operations Centers (VSOCs). Attackers are increasingly exploiting internal networks, employing tactics like CAN bus injection via physically accessible wires (e.g., disguising exploits as emergency jump-starters) or pursuing arbitrary code execution. As the industry anticipates future threats like vehicle-immobilizing ransomware, the role of security engineers must balance rigorous technical protections with seamless user experiences. Implementing robust automotive cybersecurity introduces unique constraints distinct from traditional IT. Security protocols like secure boot and onboard communication authentication must operate within strict millisecond latencies to prevent degrading vehicle performance or driver convenience. Furthermore, vehicles demand 15-year lifecycles, requiring suppliers to meticulously preserve legacy build chains for decades just to push critical software patches. At the same time, vehicle network architectures are shifting toward ECU consolidation, integrating hypervisors, containerization, and Automotive Ethernet. Reflecting the security adage that "whenever an appliance is described as being smart, it's vulnerable," this modernization inevitably increases codebase complexity and vulnerability rates. Additionally, every implemented security feature inherently spawns a new key management challenge, requiring close collaboration between suppliers and OEMs to securely provision cryptographic materials across a vehicle's lifespan. Future regulatory and technological shifts will further redefine automotive security standards. Frameworks like ISO 21434 and UNECE R155 are formalizing cybersecurity management systems, transforming risk assessment into a mandatory compliance process for vehicle homologation. Meanwhile, emerging right-to-repair legislation complicates threat models, forcing manufacturers to open diagnostic interfaces without exposing critical vehicle systems to manipulation. Looking ahead, the industry must prepare for post-quantum cryptography to protect long-lifecycle vehicles from eventual encryption obsolescence. Ultimately, as autonomous driving matures, safety and cybersecurity will converge into an inseparable co-engineering discipline, requiring advanced "black box" vehicle forensics to definitively distinguish between mechanical accidents and malicious cyber-physical exploits. **Keywords:** automotive cybersecurity, can bus injection, vehicle security operations center, ecu consolidation, iso 21434 compliance, unece r155, secure onboard communication, hardware security modules, automotive ransomware, right-to-repair cybersecurity, autonomous vehicle forensics, post-quantum cryptography, secure boot latency, legacy build chain preservation, connected vehicle attack surface ## Chapters 1. **Introduction to automotive supplier operations and vehicle systems** (00:03) — How broad manufacturing divisions manage everything from powertrain combustion to central electrical architectures. 1. **Overview of attack surfaces and cybersecurity threats** (06:08) — The transition of vehicles from offline systems to connected environments increases exposure to physical and remote exploitation. 1. **Historical milestones and the evolution of vehicle hacking** (11:25) — How early engine tuning evolved into massive remote vulnerabilities demonstrating complete control over safety critically components. 1. **Recent examples of local manipulation and physical bus attacks** (13:58) — Physical access techniques allow attackers to bypass security boundaries by directly injecting malicious packets into internal networks. 1. **Managing hardware limitations and long vehicle lifespans** (19:04) — Extending software support for decades introduces severe challenges for cryptographic performance and resource constrained environments. 1. **Securing onboard communications and defending against fault injection** (23:24) — Implementing multi-supplier message authentication requires complex synchronization to mitigate latency variations and hardware glitching techniques. 1. **Adapting to consolidated controllers and modern network architectures** (27:11) — Transitioning to fewer centralized computing units necessitates containerization and deterministic Ethernet alongside traditional automotive protocols. 1. **Evaluating software complexity and predicting emerging threat models** (29:24) — Exponential growth in codebase sizes demands rigorous static analysis and expands the operational scope for potential ransomware incidents. 1. **Navigating the complexities of cryptographic key management** (32:38) — Distributing and rotating production keys across manufacturer ecosystems requires a resilient public key infrastructure. 1. **Preserving legacy software builds and managing continuous updates** (33:51) — Delivering over-the-air firmware updates to aging architectures demands strict preservation of development toolchains to prevent accidental bricking. 1. **Balancing security architectures with right to repair legislation** (36:30) — Ensuring end users can modify hardware without exposing underlying key management workflows requires robust interface authorization. 1. **Preparing vehicle lifecycles for post quantum cryptography** (38:23) — Long production lifespans require immediate planning to transition embedded hardware accelerators before current cryptographic primitives fail. 1. **Leveraging penetration testing and vulnerability disclosure programs** (40:35) — Engaging independent security researchers through structured bounties provides external validation for complex proprietary components. 1. **Implementing automotive cybersecurity frameworks and compliance standards** (41:35) — Following specific international methodologies mandates continuous risk assessment controls across the entire manufacturing supply chain. 1. **Forensics and novel threat models in autonomous driving systems** (45:57) — Investigating algorithmic failures in self-driving cars requires tamper-proof telemetry data to distinguish physical compromise from software malfunctions. 1. **Addressing questions on artificial intelligence and usability trade-offs** (50:52) — Industry professionals discuss how generative models impact deep debugging workflows and the necessity of seamless consumer authentication. ## Related Moments - [Navigating impending automotive security regulations and compliance](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) (from "Cyber Security: Small, and Large!") - [Developer challenges in securing modern connected vehicles](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) (from "Cyber Security: Small, and Large!") - [Identifying system risks and collaborative ecosystem legal challenges](https://www.wearedevelopers.com/videos/258-on-developing-smartphones-on-wheels) (from "On developing smartphones on wheels") - [Adapting industry practices for long-term vehicle software security](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) (from "Cybersecurity for Software Defined Vehicles") - [Managing cybersecurity risks throughout the entire vehicle lifecycle](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) (from "Cybersecurity for Software Defined Vehicles") - [Approaching vehicle connectivity, offline telemetry, and software cybersecurity](https://www.wearedevelopers.com/videos/221-software-stack-under-and-over-the-hood-of-the-fastest-accelerating-car-in-the-world) (from "Software stack under and over the hood of the fastest accelerating car in the world") ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) ## Related Jobs - [Principal Product Security Architect](https://www.wearedevelopers.com/jobs/ext/1911408-principal-product-security-architect) at **ARM** - [Staff Hardware Security Engineer](https://www.wearedevelopers.com/jobs/ext/1915092-staff-hardware-security-engineer) at **Arm** - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm** - [SoC Security Architecture](https://www.wearedevelopers.com/jobs/ext/3020627-soc-security-architecture) at **ARM** - [Security IP Design Engineer](https://www.wearedevelopers.com/jobs/ext/3021047-security-ip-design-engineer) at **ARM** - [The Principal Test Engineer - Security and Provisioning](https://www.wearedevelopers.com/jobs/ext/3022499-the-principal-test-engineer-security-and-provisioning) at **ARM**