Skip to main content

Automotive software developers call on hackers to find its flaws

A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
January 20, 2017 Read time: 3 mins
A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry.

The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure software updates. Uptane is a collaboration of NYU Tandon, the University of Michigan Transport Research Institute (UMTRI), and the Southwest Research Institute (SwRI), and is supported by contracts from the US Department of Homeland Security, Science and Technology Directorate.

Modern cars contain dozens of computers, or electronic control units (ECUs), that control everything from safety equipment (airbags, brakes, engine, and transmission, and more) to entertainment systems. The increasing complexity of modern cars accompanies an increasing likelihood of flaws in the software. To combat this, vehicle makers are equipping ECUs with a secure software over-the-air (SOTA) update capability, allowing the software to be changed without visiting a service depot, resulting in fewer recalls and greater customer satisfaction. However, hackers can target these software update mechanisms to install malicious software, viruses, or even ransomware, the results of which could be catastrophic.

"Although widespread attacks are still difficult and expensive, they lie within the capabilities of nation-state cyber warriors, and it is time to begin securing the infrastructure, particularly as automotive electronics increase," Cappos said.

Uptane goes beyond TUF in order to address the unique problems posed by automotive software. For example, it allows automakers to completely control critical software but to share control when appropriate – for example, when law enforcement needs to tune a vehicle for off-road conditions. It also helps automakers to quickly deploy secure fixes for a vulnerability exploited in an attack or to remotely and inexpensively update a car's electronics.

The group has been holding regular design workgroups to develop a universal framework that could enhance the security mechanisms, protecting cars as soon as next year. As is standard practice in open-source projects, the team called upon security experts everywhere to help them find flaws in the proposed framework so that a secure final version can be adopted.

Related Content

  • ITS America's Laura Chace joins new USDoT advisory committee
    January 3, 2024
    'Transportation technology is currently not being leveraged to its full extent,' Chace says
  • Avoiding the call of the wild
    June 29, 2018
    Hitting an animal on a rural road can be fatal for all parties involved – but detecting and avoiding them requires clever technology. Andrew Williams carefully scans the horizon for details. Wildlife-vehicle collisions are an ever-present threat in rural areas around the world, and there is certainly nothing funny about suddenly finding an angry moose in your headlights on a sharp bend. A variety of detection and avoidance systems are currently in use or under development to help prevent your vehicle being
  • More than 20 million connected cars with built-in software-based security by 2020
    February 14, 2014
    The findings of ABI Research’s Automotive Safety & Autonomous Driving and Cybersecurity Research Services indicate that while traditional safety telematics services such as eCall, bCall, stolen vehicle tracking, and diagnostics aimed at the physical protection of vehicles, drivers and passengers are becoming main stream, awareness is growing about the threat of cyber-attacks and their impact on the physical integrity of persons, especially with vehicle-to-vehicle communication and autonomous vehicles. This
  • Here beats Google as world’s leading location platform, says Ovum
    August 23, 2018
    Here Technologies has toppled Google as the world’s leading location platform, according to a new report. The Dutch mapping company’s price plan appears more developer-friendly and competitive than the Google Maps model, says analyst Ovum. Location Platform Index: Mapping and Navigation ranked 14 major location platform vendors according to their mapping and technology as well as the size of their reach across the developer communities and industries. Here’s Freemium model is intended to lower price