Skip to main content

2018 | OriginalPaper | Buchkapitel

Safe and Secure Automotive Over-the-Air Updates

verfasst von : Thomas Chowdhury, Eric Lesiuta, Kerianne Rikley, Chung-Wei Lin, Eunsuk Kang, BaekGyu Kim, Shinichi Shiraishi, Mark Lawford, Alan Wassyng

Erschienen in: Computer Safety, Reliability, and Security

Verlag: Springer International Publishing

Aktivieren Sie unsere intelligente Suche, um passende Fachinhalte oder Patente zu finden.

search-config
loading …

Abstract

Over-the-air updates have been used for years in the software industry, allowing bug fixes and enhancements to desktop, laptop, and mobile operating systems and applications. Automotive vehicles now depend on software to the extent that manufacturers are turning to over-the-air updates for critical vehicle functionality. History shows that our software systems are most vulnerable to lapses in safety and dependability when they undergo change, and performing an update over a communication channel adds a significant security concern. This paper presents our ideas on assuring integrated safety and security of over-the-air updates through assurance case templates that comply with both ISO 26262 (functional safety) and SAE J3061 (cyber-security). Wisely, the authors of SAE J3061 structured the guidebook so that it meshes well with ISO 26262, and we have been able to use principles we developed for deriving an assurance case template from ISO 26262, to help include compliance with SAE J3061 in the template. The paper also demonstrates how a specialization of the template helps guide us to pre-emptively mitigate against potential vulnerabilities in over-the-air update implementations.

Sie haben noch keine Lizenz? Dann Informieren Sie sich jetzt über unsere Produkte:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Literatur
2.
Zurück zum Zitat Aroms, E., et al.: NIST Special Publication 800–30 Risk Management Guide for Information Technology Systems (2012) Aroms, E., et al.: NIST Special Publication 800–30 Risk Management Guide for Information Technology Systems (2012)
5.
Zurück zum Zitat Bloomfield, R., Bishop, P., Jones, C., Froome, P.: ASCAD. Adelard Safety Case Development Manual, Adelard (1998). ISBN 0-9533771-0 5 Bloomfield, R., Bishop, P., Jones, C., Froome, P.: ASCAD. Adelard Safety Case Development Manual, Adelard (1998). ISBN 0-9533771-0 5
7.
Zurück zum Zitat Chowdhury, T., Lin, C.W., Kim, B., Lawford, M., Shiraishi, S., Wassyng, A.: Principles for systematic development of an assurance case template from ISO 26262. In: IEEE International Symposium on Software Reliability Engineering, pp. 69–72, October 2017 Chowdhury, T., Lin, C.W., Kim, B., Lawford, M., Shiraishi, S., Wassyng, A.: Principles for systematic development of an assurance case template from ISO 26262. In: IEEE International Symposium on Software Reliability Engineering, pp. 69–72, October 2017
8.
Zurück zum Zitat Friedberg, I., McLaughlin, K., Smith, P., Laverty, D., Sezer, S.: STPA-SafeSec: safety and security analysis for cyber-physical systems. J. Inf. Secur. Appl. 34, 183–196 (2017) Friedberg, I., McLaughlin, K., Smith, P., Laverty, D., Sezer, S.: STPA-SafeSec: safety and security analysis for cyber-physical systems. J. Inf. Secur. Appl. 34, 183–196 (2017)
9.
Zurück zum Zitat Graydon, P., Knight, J., Strunk, E.: Assurance based development of critical systems. In: 37th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2007, pp. 347–357, June 2007 Graydon, P., Knight, J., Strunk, E.: Assurance based development of critical systems. In: 37th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2007, pp. 347–357, June 2007
10.
Zurück zum Zitat ISO: 26262: Road vehicles-Functional safety. International Standard ISO 26262 (2011) ISO: 26262: Road vehicles-Functional safety. International Standard ISO 26262 (2011)
11.
Zurück zum Zitat ISO/SAE AWI: 21434: Road vehicles-Cybersecurity Engineering [Under development] ISO/SAE AWI: 21434: Road vehicles-Cybersecurity Engineering [Under development]
12.
Zurück zum Zitat ISO/WD PAS: 21448: Road vehicles - Safety of the intended functionality [Under development] ISO/WD PAS: 21448: Road vehicles - Safety of the intended functionality [Under development]
13.
Zurück zum Zitat Karthik, T., Brown, A., Awwad, S., McCoy, D., Bielawski, R., Mott, C., Lauzon, S., Weimerskirch, A., Cappos, J.: Uptane: securing software updates for automobiles. In: International Conference on Embedded Security in Car, pp. 1–11 (2016) Karthik, T., Brown, A., Awwad, S., McCoy, D., Bielawski, R., Mott, C., Lauzon, S., Weimerskirch, A., Cappos, J.: Uptane: securing software updates for automobiles. In: International Conference on Embedded Security in Car, pp. 1–11 (2016)
14.
Zurück zum Zitat Kelly, T.: Arguing safety - a systematic approach to managing safety cases. Ph.D. thesis, University of York, September 1998 Kelly, T.: Arguing safety - a systematic approach to managing safety cases. Ph.D. thesis, University of York, September 1998
15.
Zurück zum Zitat Lauzon, S.: Secure software updates for automotive systems: introduction to the Uptane SOTA solution, May 2017 Lauzon, S.: Secure software updates for automotive systems: introduction to the Uptane SOTA solution, May 2017
16.
Zurück zum Zitat Leveson, N.: Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Cambridge (2011) Leveson, N.: Engineering a Safer World: Systems Thinking Applied to Safety. MIT Press, Cambridge (2011)
17.
Zurück zum Zitat Macher, G., Armengaud, E., Brenner, E., Kreiner, C.: Threat and risk assessment methodologies in the automotive domain. Procedia Comput. Sci. 83, 1288–1294 (2016)CrossRef Macher, G., Armengaud, E., Brenner, E., Kreiner, C.: Threat and risk assessment methodologies in the automotive domain. Procedia Comput. Sci. 83, 1288–1294 (2016)CrossRef
21.
Zurück zum Zitat Netkachova, K., Müller, K., Paulitsch, M., Bloomfield, R.: Security-informed safety case approach to analysing MILS systems (2015) Netkachova, K., Müller, K., Paulitsch, M., Bloomfield, R.: Security-informed safety case approach to analysing MILS systems (2015)
23.
Zurück zum Zitat Procter, S., Vasserman, E.Y., Hatcliff, J.: Safe and secure: deeply integrating security in a new hazard analysis. In: ARES, p. 66. ACM (2017) Procter, S., Vasserman, E.Y., Hatcliff, J.: Safe and secure: deeply integrating security in a new hazard analysis. In: ARES, p. 66. ACM (2017)
24.
Zurück zum Zitat SAE International: SAE J3061-Cybersecurity Guidebook for Cyber-Physical Automotive Systems. SAE-Society of Automotive Engineers (2016) SAE International: SAE J3061-Cybersecurity Guidebook for Cyber-Physical Automotive Systems. SAE-Society of Automotive Engineers (2016)
25.
Zurück zum Zitat Shostack, A.: Threat Modeling: Designing for Security. Wiley, Hoboken (2014) Shostack, A.: Threat Modeling: Designing for Security. Wiley, Hoboken (2014)
26.
Zurück zum Zitat Spaan, R., Batina, L., Schwabe, P., Verheijden, S.: Secure updates in automotive systems, pp. 1–71. Radboud University, Nijmegen (2016) Spaan, R., Batina, L., Schwabe, P., Verheijden, S.: Secure updates in automotive systems, pp. 1–71. Radboud University, Nijmegen (2016)
29.
Zurück zum Zitat Wassyng, A., Joannou, P., Lawford, M., Maibaum, T.S., Singh, N.K.: Chapter 13 new standards for trustworthy cyber-physical systems. In: Trustworthy Cyber-Physical Systems Engineering, pp. 337–368. CRC Press (2016) Wassyng, A., Joannou, P., Lawford, M., Maibaum, T.S., Singh, N.K.: Chapter 13 new standards for trustworthy cyber-physical systems. In: Trustworthy Cyber-Physical Systems Engineering, pp. 337–368. CRC Press (2016)
32.
Zurück zum Zitat Young, W., Leveson, N.: Systems thinking for safety and security. In: Proceedings of the 29th Annual Computer Security Applications Conference, pp. 1–8. ACM (2013) Young, W., Leveson, N.: Systems thinking for safety and security. In: Proceedings of the 29th Annual Computer Security Applications Conference, pp. 1–8. ACM (2013)
Metadaten
Titel
Safe and Secure Automotive Over-the-Air Updates
verfasst von
Thomas Chowdhury
Eric Lesiuta
Kerianne Rikley
Chung-Wei Lin
Eunsuk Kang
BaekGyu Kim
Shinichi Shiraishi
Mark Lawford
Alan Wassyng
Copyright-Jahr
2018
DOI
https://doi.org/10.1007/978-3-319-99130-6_12

Premium Partner