Skip to main content

Automotive software developers call on hackers to find its flaws

A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
January 20, 2017 Read time: 3 mins
A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry.

The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure software updates. Uptane is a collaboration of NYU Tandon, the University of Michigan Transport Research Institute (UMTRI), and the Southwest Research Institute (SwRI), and is supported by contracts from the US Department of Homeland Security, Science and Technology Directorate.

Modern cars contain dozens of computers, or electronic control units (ECUs), that control everything from safety equipment (airbags, brakes, engine, and transmission, and more) to entertainment systems. The increasing complexity of modern cars accompanies an increasing likelihood of flaws in the software. To combat this, vehicle makers are equipping ECUs with a secure software over-the-air (SOTA) update capability, allowing the software to be changed without visiting a service depot, resulting in fewer recalls and greater customer satisfaction. However, hackers can target these software update mechanisms to install malicious software, viruses, or even ransomware, the results of which could be catastrophic.

"Although widespread attacks are still difficult and expensive, they lie within the capabilities of nation-state cyber warriors, and it is time to begin securing the infrastructure, particularly as automotive electronics increase," Cappos said.

Uptane goes beyond TUF in order to address the unique problems posed by automotive software. For example, it allows automakers to completely control critical software but to share control when appropriate – for example, when law enforcement needs to tune a vehicle for off-road conditions. It also helps automakers to quickly deploy secure fixes for a vulnerability exploited in an attack or to remotely and inexpensively update a car's electronics.

The group has been holding regular design workgroups to develop a universal framework that could enhance the security mechanisms, protecting cars as soon as next year. As is standard practice in open-source projects, the team called upon security experts everywhere to help them find flaws in the proposed framework so that a secure final version can be adopted.

Related Content

  • September 13, 2016
    Volvo and KPMG find buses are key to urban air quality
    Buses can play a key role in the battle to improve air quality in towns and cities as David Crawford discovers. A city with a population of half a million would gain about US$12.3 million in annualised societal savings if all its buses ran on electricity instead of diesel. This is the conclusion of a wide-ranging analysis carried out by Swedish bus manufacturer Volvo Group and global business consultants KPMG.
  • November 7, 2013
    Smart Spanish city trials cell-based traffic management
    David Crawford reports on an urban electronic nervous system. The northern Spanish city of Santander – historically a port - is now an emerging technology showcase attracting global attention as a prototype for a medium-sized smart city of the future. In a move to determine the optimal use of available data, it is creating a de-facto experimental laboratory for sensor and mobile phone-based urban traffic management and environmental monitoring innovations.
  • July 29, 2013
    Weathering the elements: how weather affects the network
    Weather-related problems can render cost-cutting counter productive, according to CommScope’s Philip Sorrells. When severe weather conditions make headlines every winter, motorists and travellers seem willing to accept the impact on the trains and roads and yet take for granted that the communications networks will continue uninterrupted. They often appear far more upset that the information system does not give them an update on road conditions, train services or bus arrival times than they are about the a
  • December 2, 2013
    Auto safety initiative seeks to reduce driver errors
    A push by the US National Highway Traffic Safety Administration to use technology to reduce traffic fatalities aims to keep drunk drivers off the roads by using in-vehicle technology that immobilises their cars. They are pushing for systems that prevent drivers from starting their cars, help cars avoid collisions and prevent vehicles from starting if the occupants don’t wear seat belts. "Ninety per cent of all crashes have an element of human error," NHTSA administrator David Strickland said. "We really