Skip to main content

Automotive software developers call on hackers to find its flaws

A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
January 20, 2017 Read time: 3 mins
A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry.

The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure software updates. Uptane is a collaboration of NYU Tandon, the University of Michigan Transport Research Institute (UMTRI), and the Southwest Research Institute (SwRI), and is supported by contracts from the US Department of Homeland Security, Science and Technology Directorate.

Modern cars contain dozens of computers, or electronic control units (ECUs), that control everything from safety equipment (airbags, brakes, engine, and transmission, and more) to entertainment systems. The increasing complexity of modern cars accompanies an increasing likelihood of flaws in the software. To combat this, vehicle makers are equipping ECUs with a secure software over-the-air (SOTA) update capability, allowing the software to be changed without visiting a service depot, resulting in fewer recalls and greater customer satisfaction. However, hackers can target these software update mechanisms to install malicious software, viruses, or even ransomware, the results of which could be catastrophic.

"Although widespread attacks are still difficult and expensive, they lie within the capabilities of nation-state cyber warriors, and it is time to begin securing the infrastructure, particularly as automotive electronics increase," Cappos said.

Uptane goes beyond TUF in order to address the unique problems posed by automotive software. For example, it allows automakers to completely control critical software but to share control when appropriate – for example, when law enforcement needs to tune a vehicle for off-road conditions. It also helps automakers to quickly deploy secure fixes for a vulnerability exploited in an attack or to remotely and inexpensively update a car's electronics.

The group has been holding regular design workgroups to develop a universal framework that could enhance the security mechanisms, protecting cars as soon as next year. As is standard practice in open-source projects, the team called upon security experts everywhere to help them find flaws in the proposed framework so that a secure final version can be adopted.

Related Content

  • January 26, 2015
    Ford Opens new Silicon Valley research centre
    Ford’s newly opened Research and Innovation Center Palo Alto, US, will drive the company’s innovation in connectivity, mobility, autonomous vehicles, customer experience and big data, it says. The new research centre will continue the company’s work on autonomous vehicles, including ongoing work with University of Michigan and Massachusetts Institute of Technology. It will also expand collaboration with Stanford University that started in 2013 and will contribute a Fusion autonomous research vehicle to t
  • March 26, 2013
    Creating safer roads with vehicle communication
    Accurate, timely information which eliminates the need to brake quickly when approaching a work zone or other road hazard could prevent crashes and save lives, according to research by the University of Minnesota. Thanks to research by the University of Minnesota, this vision is closer than ever to reality. “In the past fifty years we’ve made great strides in reducing traffic fatalities with technologies that save lives in crashes, like airbags and seat belts,” says M. Imram Hayee, electrical and computer e
  • May 21, 2012
    Audi Urban Intelligent Assist research programme launched
    A new research initiative launched by Audi, its electronics research laboratory in Silicon Valley and four top US universities aims to develop technologies focused on easing the congestion, dangers and inconveniences that often confront drivers in the world's biggest cities. The new three-year Audi Urban Intelligent Assist research initiative aims to take connected car, driver assistance and infrastructure electronics to the next level of providing detailed information so motorists have a better sense of th
  • March 6, 2015
    Visionary UK strategy ‘needed to unblock benefits of new motoring technologies’
    The UK government Transport Select Committee has called for a Visionary UK strategy to maximise benefits of new motoring technology in its report, Motoring of the Future. The committee says new automotive technologies could unblock congested highways, deliver a step change in road safety and provide the basis for rapid industrial growth, but the Department for Transport (DfT) will need to develop a comprehensive strategy to maximise the benefits of new motoring technology, such as telematics and driverless