> Markdown version of [/videos/725-cybersecurity-for-software-defined-vehicles?t=351](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles?t=351). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity for Software Defined Vehicles Modern cars run over 100 million lines of code, transforming them into vulnerable rolling endpoints. How can engineers leverage strict domain isolation and cryptography to thwart remote exploits? - **Speakers:** Henning Harbs - **Event:** World Congress 2023 - **Published:** September 27, 2023 - **Duration:** 22:09 - **URL:** https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles ## Summary The automotive industry's transition from hardware-centric designs to software-defined vehicles (SDVs) involves integrating up to 100 electronic control units (ECUs) and over 100 million lines of code per car. While this profound connectivity enables advanced mobility services and remote functionality, it vastly expands the attack surface. Traditional physical locks are no longer sufficient; engineers must now defend against remote exploits, arbitrary code execution, and physical tampering methods like CAN injection via the legacy OBD port. To standardize defenses, frameworks such as UNECE Regulation 155 legally mandate that original equipment manufacturers (OEMs) and their component suppliers implement comprehensive Cybersecurity Management Systems (CSMS). Because vehicles have road lifespans exceeding a decade, security cannot end at the factory door. Automakers are adopting practices similar to the aviation industry, requiring continuous threat monitoring, incident response protocols, and secure over-the-air (OTA) patching capabilities to maintain fleet integrity throughout the vehicle's entire lifecycle. Mitigating real-world threats—such as brute-forced cryptographic keys and keyless entry relay attacks—requires specialized technical solutions. Modern security toolkits rely on Hardware Security Modules (HSM) for in-car cryptographic provisioning and ultra-wideband (UWB) signaling to thwart relay theft via time-of-flight validation. Furthermore, manufacturers are moving toward secure service-oriented architectures (SOA) and strict domain isolation, utilizing structural gateways to ensure that vulnerabilities in passenger infotainment networks cannot compromise critical mobility and steering systems. **Keywords:** software-defined vehicle security, UNECE 155 compliance, automotive cybersecurity management, over-the-air vehicle updates, ECU vulnerability mitigation, secure service-oriented architecture, CAN bus injection attacks, hardware security module implementation, ultra-wideband keyless entry, OBD port security, automotive domain isolation, vehicle lifecycle threat monitoring, infotainment code execution risks, automotive intrusion detection, relay attack prevention ## Chapters 1. **Transitioning from hardware to software-defined vehicle architectures** (00:03) — Transitioning automotive designs to software-centric platforms introduces architectural complexity alongside new capabilities for remote applications. 1. **Connected vehicle attack vectors and international cybersecurity regulations** (02:40) — Increased vehicle connectivity exposes new attack vectors and necessitates compliance with strict frameworks like the UNECE 155 regulation. 1. **Managing cybersecurity risks throughout the entire vehicle lifecycle** (05:51) — Maintaining ongoing security requires continuous threat monitoring, incident response frameworks, and over-the-air software updates over decades. 1. **Securing vehicle networks with hardware modules and strong cryptography** (09:41) — Implementing service-oriented communication manifests and hardware secure modules protects internal components from unauthorized access and rogue diagnostics devices. 1. **Analyzing real world vehicle vulnerabilities and keyless theft attacks** (13:43) — Hackers exploit weak encryption, CAN injection, and signal relaying techniques on key fobs to steal modern vehicles. 1. **Adapting industry practices for long-term vehicle software security** (17:46) — Automotive companies must revamp development paradigms and value chains to meet compliance and ensure vehicles remain reliably patchable. 1. **Audience questions on securing legacy buses and architecture isolation** (19:10) — The transition to ethernet networking does not eliminate the need for strict ECU isolation and adherence to standards like AUTOSAR. ## Related Moments - [Developer challenges in securing modern connected vehicles](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) (from "Cyber Security: Small, and Large!") - [Approaching vehicle connectivity, offline telemetry, and software cybersecurity](https://www.wearedevelopers.com/videos/221-software-stack-under-and-over-the-hood-of-the-fastest-accelerating-car-in-the-world) (from "Software stack under and over the hood of the fastest accelerating car in the world") - [Navigating impending automotive security regulations and compliance](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) (from "Cyber Security: Small, and Large!") - [Identifying system risks and collaborative ecosystem legal challenges](https://www.wearedevelopers.com/videos/258-on-developing-smartphones-on-wheels) (from "On developing smartphones on wheels") - [Validating external integration security against cyber vulnerabilities](https://www.wearedevelopers.com/videos/200-agile-work-at-cariad-creating-a-customer-web-application-for-controlling-the-vehicle) (from "Agile work at CARIAD – Creating a customer web application for controlling the vehicle ") - [Tackling functional complexity with localized vehicle electronic architectures](https://www.wearedevelopers.com/videos/258-on-developing-smartphones-on-wheels) (from "On developing smartphones on wheels") ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) ## Related Jobs - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Endpoint Security Engineer - OT](https://www.wearedevelopers.com/jobs/ext/1306782-endpoint-security-engineer-ot) at **ZEISS Group** - [Endpoint Security Engineer - OT](https://www.wearedevelopers.com/jobs/ext/1998712-endpoint-security-engineer-ot) at **ZEISS Group** - [Endpoint Security Engineer](https://www.wearedevelopers.com/jobs/ext/1962698-endpoint-security-engineer) at **ZEISS Group** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Cyber Security Architect](https://www.wearedevelopers.com/jobs/ext/1210090-cyber-security-architect) at **BWI GmbH**