Skip to main content

Automotive software developers call on hackers to find its flaws

A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
January 20, 2017 Read time: 3 mins
A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry.

The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure software updates. Uptane is a collaboration of NYU Tandon, the University of Michigan Transport Research Institute (UMTRI), and the Southwest Research Institute (SwRI), and is supported by contracts from the US Department of Homeland Security, Science and Technology Directorate.

Modern cars contain dozens of computers, or electronic control units (ECUs), that control everything from safety equipment (airbags, brakes, engine, and transmission, and more) to entertainment systems. The increasing complexity of modern cars accompanies an increasing likelihood of flaws in the software. To combat this, vehicle makers are equipping ECUs with a secure software over-the-air (SOTA) update capability, allowing the software to be changed without visiting a service depot, resulting in fewer recalls and greater customer satisfaction. However, hackers can target these software update mechanisms to install malicious software, viruses, or even ransomware, the results of which could be catastrophic.

"Although widespread attacks are still difficult and expensive, they lie within the capabilities of nation-state cyber warriors, and it is time to begin securing the infrastructure, particularly as automotive electronics increase," Cappos said.

Uptane goes beyond TUF in order to address the unique problems posed by automotive software. For example, it allows automakers to completely control critical software but to share control when appropriate – for example, when law enforcement needs to tune a vehicle for off-road conditions. It also helps automakers to quickly deploy secure fixes for a vulnerability exploited in an attack or to remotely and inexpensively update a car's electronics.

The group has been holding regular design workgroups to develop a universal framework that could enhance the security mechanisms, protecting cars as soon as next year. As is standard practice in open-source projects, the team called upon security experts everywhere to help them find flaws in the proposed framework so that a secure final version can be adopted.

Related Content

  • US DoT launches largest-ever road test of connected vehicle crash avoidance technology
    August 22, 2012
    Nearly 3,000 cars, trucks and buses equipped with connected Wi-Fi technology to enable vehicles and infrastructure to ‘talk’ to each other in real time to help avoid crashes and improve traffic flow, began traversing Ann Arbor's streets yesterday as part of a year-long safety pilot project by the US Department of Transportation. Ray LaHood, US Transportation Secretary, joined elected officials and industry and community leaders on the University of Michigan campus to launch the second phase of the Safety Pi
  • Volvo and KPMG find buses are key to urban air quality
    September 13, 2016
    Buses can play a key role in the battle to improve air quality in towns and cities as David Crawford discovers. A city with a population of half a million would gain about US$12.3 million in annualised societal savings if all its buses ran on electricity instead of diesel. This is the conclusion of a wide-ranging analysis carried out by Swedish bus manufacturer Volvo Group and global business consultants KPMG.
  • Smart Spanish city trials cell-based traffic management
    November 7, 2013
    David Crawford reports on an urban electronic nervous system. The northern Spanish city of Santander – historically a port - is now an emerging technology showcase attracting global attention as a prototype for a medium-sized smart city of the future. In a move to determine the optimal use of available data, it is creating a de-facto experimental laboratory for sensor and mobile phone-based urban traffic management and environmental monitoring innovations.
  • Weathering the elements: how weather affects the network
    July 29, 2013
    Weather-related problems can render cost-cutting counter productive, according to CommScope’s Philip Sorrells. When severe weather conditions make headlines every winter, motorists and travellers seem willing to accept the impact on the trains and roads and yet take for granted that the communications networks will continue uninterrupted. They often appear far more upset that the information system does not give them an update on road conditions, train services or bus arrival times than they are about the a