Skip to main content

Automotive software developers call on hackers to find its flaws

A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
January 20, 2017 Read time: 3 mins
A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry.

The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure software updates. Uptane is a collaboration of NYU Tandon, the University of Michigan Transport Research Institute (UMTRI), and the Southwest Research Institute (SwRI), and is supported by contracts from the US Department of Homeland Security, Science and Technology Directorate.

Modern cars contain dozens of computers, or electronic control units (ECUs), that control everything from safety equipment (airbags, brakes, engine, and transmission, and more) to entertainment systems. The increasing complexity of modern cars accompanies an increasing likelihood of flaws in the software. To combat this, vehicle makers are equipping ECUs with a secure software over-the-air (SOTA) update capability, allowing the software to be changed without visiting a service depot, resulting in fewer recalls and greater customer satisfaction. However, hackers can target these software update mechanisms to install malicious software, viruses, or even ransomware, the results of which could be catastrophic.

"Although widespread attacks are still difficult and expensive, they lie within the capabilities of nation-state cyber warriors, and it is time to begin securing the infrastructure, particularly as automotive electronics increase," Cappos said.

Uptane goes beyond TUF in order to address the unique problems posed by automotive software. For example, it allows automakers to completely control critical software but to share control when appropriate – for example, when law enforcement needs to tune a vehicle for off-road conditions. It also helps automakers to quickly deploy secure fixes for a vulnerability exploited in an attack or to remotely and inexpensively update a car's electronics.

The group has been holding regular design workgroups to develop a universal framework that could enhance the security mechanisms, protecting cars as soon as next year. As is standard practice in open-source projects, the team called upon security experts everywhere to help them find flaws in the proposed framework so that a secure final version can be adopted.

Related Content

  • December 17, 2014
    Growth of global connected car M2M connections and services market
    The latest research by ReportsnReports.com, Global Connected Car M2M Connections and Services Market indicates that big data analytics and smart phone apps will foster the growth of the global connected car M2M connections and services market, which will see a 32 per cent CAGR for 2014-2019. According to the report, many big data analytic and automobile companies are joining forces with smart app providers to form partnerships to better understand vehicle performance and automotive businesses. Smart apps
  • December 2, 2016
    Cars reinvented: huge new opportunities and dangers, says IDTechEx
    The new IDTechEx report, Electric Car Technology and Forecasts 2017-2027 finds that the biggest change in cars for one hundred years is now starting. It is driven by totally new requirements and capabilities. They will cause huge new businesses to appear but some giants currently making cars and their parts will spectacularly go bankrupt. Cities will ban private cars but encourage cars as autonomous taxis and rental vehicles. Already 65 per cent of cars in China are bought by businesses. The Japanese wa
  • June 4, 2015
    The future looks bright for ITS
    Professor Eric Sampson talks about the past successes of ITS, its potential for the future and the challenges the industry faces. If anybody should know when Intelligent Transport Systems started that person is Professor Eric Sampson, a visiting professor at both Newcastle and London City Universities. Having spent 40 years working for the UK’s Department of Transport and other public administrations, Professor Sampson now supports the European Commission on ITS systems and advises ERTICO ITS-Europe and ITS
  • October 19, 2022
    Leonardo addresses new mobility trends
    Italy-headquartered Leonardo outlines why, and how, the company is at the forefront of more effective, efficient, and sustainable mobility - a top European priority - through investments in the Next Generation EU programme, aimed at achieving energy and climatic objectives.