Skip to main content

Automotive software developers call on hackers to find its flaws

A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry. The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure
January 20, 2017 Read time: 3 mins
A consortium of US researchers has announced the development of a universal, free, and open-source framework to protect wireless software updates in vehicles. The team issued a challenge to security experts everywhere to try to find vulnerabilities before it is adopted by the automotive industry.

The new solution, called Uptane, evolves the widely used TUF (The Update Framework), developed by NYU Tandon School of Engineering Assistant Professor of Computer Science and Engineering Justin Cappos to secure software updates. Uptane is a collaboration of NYU Tandon, the University of Michigan Transport Research Institute (UMTRI), and the Southwest Research Institute (SwRI), and is supported by contracts from the US Department of Homeland Security, Science and Technology Directorate.

Modern cars contain dozens of computers, or electronic control units (ECUs), that control everything from safety equipment (airbags, brakes, engine, and transmission, and more) to entertainment systems. The increasing complexity of modern cars accompanies an increasing likelihood of flaws in the software. To combat this, vehicle makers are equipping ECUs with a secure software over-the-air (SOTA) update capability, allowing the software to be changed without visiting a service depot, resulting in fewer recalls and greater customer satisfaction. However, hackers can target these software update mechanisms to install malicious software, viruses, or even ransomware, the results of which could be catastrophic.

"Although widespread attacks are still difficult and expensive, they lie within the capabilities of nation-state cyber warriors, and it is time to begin securing the infrastructure, particularly as automotive electronics increase," Cappos said.

Uptane goes beyond TUF in order to address the unique problems posed by automotive software. For example, it allows automakers to completely control critical software but to share control when appropriate – for example, when law enforcement needs to tune a vehicle for off-road conditions. It also helps automakers to quickly deploy secure fixes for a vulnerability exploited in an attack or to remotely and inexpensively update a car's electronics.

The group has been holding regular design workgroups to develop a universal framework that could enhance the security mechanisms, protecting cars as soon as next year. As is standard practice in open-source projects, the team called upon security experts everywhere to help them find flaws in the proposed framework so that a secure final version can be adopted.

Related Content

  • Bhatt: 'Critical opportunity' for cybersecurity
    July 22, 2021
    ITS America CEO Shailen Bhatt tells US Senate funds are needed to 'manage vulnerabilities'
  • Slovenian police get smart with truckers
    March 22, 2012
    Writing in the newsletter of TISPOL, an organisation established by the traffic police forces of Europe to improve road safety and law enforcement on the roads of Europe, Danijel Kumberger, National Traffic Police Unit, Slovenia, has revealed how smart the force has had to become to catch law-breaking truckers. As he points out, with automotive technical progress, it is vital to keep in touch with innovation because in modern vehicles, it is all about electronics, data sharing and processing of all kinds of
  • Who’s connecting to your car?
    September 17, 2013
    Development services company Symphony Teleca (STC) and Guardtime, provider of keyless signature infrastructure (KSI) software and solutions are to partner in a deal that will develop security, safety, maintenance, and reliability capabilities to enhance the connected car.
  • Advanced telematics and integration to revolutionise global connected car market
    May 22, 2015
    Advanced infotainment systems, over-the-air (OTA) updates, big data analytics, mobility services and in-car security are key technologies that will shape the global connected car market in 2015. Human machine interface (HMI) input and output solutions, as well as, heads up display (HUD) are set to take centre stage. However, car makers must create consumer-centric HMI solutions that will strike a balance between reducing driver distraction and meeting consumer need for connected services. New analysis f