WeAreDevelopers LIVE • Apr 27, 2023

Automotive Security Challenges: A Supplier's View

Davor Frkat

Attackers are disguising CAN bus exploits as emergency jump-starters to compromise software-defined vehicles. Discover how suppliers secure modern fleets against ransomware without sacrificing strict millisecond latency requirements.

Pause
Mute Enter Fullscreen
#1 about 7 min

Introduction to automotive supplier operations and vehicle systems

How broad manufacturing divisions manage everything from powertrain combustion to central electrical architectures.

#2 about 6 min

Overview of attack surfaces and cybersecurity threats

The transition of vehicles from offline systems to connected environments increases exposure to physical and remote exploitation.

#3 about 3 min

Historical milestones and the evolution of vehicle hacking

How early engine tuning evolved into massive remote vulnerabilities demonstrating complete control over safety critically components.

#4 about 6 min

Recent examples of local manipulation and physical bus attacks

Physical access techniques allow attackers to bypass security boundaries by directly injecting malicious packets into internal networks.

#5 about 5 min

Managing hardware limitations and long vehicle lifespans

Extending software support for decades introduces severe challenges for cryptographic performance and resource constrained environments.

#6 about 4 min

Securing onboard communications and defending against fault injection

Implementing multi-supplier message authentication requires complex synchronization to mitigate latency variations and hardware glitching techniques.

#7 about 3 min

Adapting to consolidated controllers and modern network architectures

Transitioning to fewer centralized computing units necessitates containerization and deterministic Ethernet alongside traditional automotive protocols.

#8 about 4 min

Evaluating software complexity and predicting emerging threat models

Exponential growth in codebase sizes demands rigorous static analysis and expands the operational scope for potential ransomware incidents.

#9 about 2 min

Navigating the complexities of cryptographic key management

Distributing and rotating production keys across manufacturer ecosystems requires a resilient public key infrastructure.

#10 about 3 min

Preserving legacy software builds and managing continuous updates

Delivering over-the-air firmware updates to aging architectures demands strict preservation of development toolchains to prevent accidental bricking.

#11 about 2 min

Balancing security architectures with right to repair legislation

Ensuring end users can modify hardware without exposing underlying key management workflows requires robust interface authorization.

#12 about 3 min

Preparing vehicle lifecycles for post quantum cryptography

Long production lifespans require immediate planning to transition embedded hardware accelerators before current cryptographic primitives fail.

#13 about 1 min

Leveraging penetration testing and vulnerability disclosure programs

Engaging independent security researchers through structured bounties provides external validation for complex proprietary components.

#14 about 5 min

Implementing automotive cybersecurity frameworks and compliance standards

Following specific international methodologies mandates continuous risk assessment controls across the entire manufacturing supply chain.

#15 about 5 min

Forensics and novel threat models in autonomous driving systems

Investigating algorithmic failures in self-driving cars requires tamper-proof telemetry data to distinguish physical compromise from software malfunctions.

#16 about 9 min

Addressing questions on artificial intelligence and usability trade-offs

Industry professionals discuss how generative models impact deep debugging workflows and the necessity of seamless consumer authentication.

Matching moments

1:35 min

Navigating impending automotive security regulations and compliance

Martin Schmiedecker · LIVE

4:36 min

Developer challenges in securing modern connected vehicles

Martin Schmiedecker · LIVE

11:26 min

Identifying system risks and collaborative ecosystem legal challenges

Hans-Jürgen Eidler · LIVE

1:23 min

Adapting industry practices for long-term vehicle software security

Henning Harbs · World Congress 2023

3:50 min

Managing cybersecurity risks throughout the entire vehicle lifecycle

Henning Harbs · World Congress 2023

5:14 min

Approaching vehicle connectivity, offline telemetry, and software cybersecurity

Denis Grahovac · World Congress 2021