Skip to main content

Making connections without compromising security

We listen in as global experts discuss connected vehicles and cybersecurity. By 2019 there will be almost 44 million connected cars globally and by 2022 that figure will be nearer 70 million; some 40% will be electric powered, according to market analyst Frost & Sullivan. But its report said the issue of end-to-end security for the new technology is still under debate, as vehicle OEMs engage with vendors to test specific security application areas for both over-the-air and vehicle-to-exterior services.
November 10, 2017 Read time: 4 mins
It is not only new vehicles like the ones rolling off Fiat Chrysler’s assembly line that will be connected.
We listen in as global experts discuss connected vehicles and cybersecurity.


By 2019 there will be almost 44 million connected cars globally and by 2022 that figure will be nearer 70 million; some 40% will be electric powered, according to market analyst 2097 Frost & Sullivan. But its report said the issue of end-to-end security for the new technology is still under debate, as vehicle OEMs engage with vendors to test specific security application areas for both over-the-air and vehicle-to-exterior services.

Traditionally, the car has been a secure, closed environment. But connected vehicles (CVs) are potentially open, and thus of interest to the maliciously-minded, with more than 50 points of vulnerability that can be used to threaten people’s lives and automakers’ reputation.  

A webinar hosted by Frost and Sullivan’s head of digital transformation, Jean-Noël Georges, discussed the current state of play with Christine Caviglioli (vice-president of automotive of digital security specialist M2M Gemalto) and Yvan Gravier, CEO of French CV open data startup Eliocity.  

Cybersecurity management and the building up of consumer confidence will be the two decisive factors for the continued growth of the CV sector, warned Georges. He cited Fiat Chrysler’s voluntary safety recall of some 1.4 million cars and trucks equipped with radios that enable remote updating of the in-vehicle software.

The recall, to check the vehicles’ security against possible imitation attacks by hackers, followed the high-profile cyberjacking of a Cherokee Jeep. Those responsible were able to remotely manipulate some of the vehicle’s critical functions, including transmission, steering and brakes. At that time Fiat Chrysler stated that, to its knowledge, there had not been a real-world incident of remote hacking into any of its vehicles and that the recall had found no defects.

“But,” stressed Georges, “it is now becoming obligatory for auto-industry OEMs to actively pursue cybersecurity measures rather than simply trying to mitigate the risks.” These can include breaking into cloud infrastructures, ‘sniffing’ data from communications networks and intruding into a vehicle’s engine control unit or infotainment system.

“Once these risks are being better planned for, however”, he continued, “the CV revolution will prove to be a fantastic opportunity for the traditional players to reinvent the way in which consumers interact with automakers and their vehicles.” He pointed to the likes of Apple CarPlay and Android Auto, which are already making themselves felt in the connected car market; with Apple nurturing plans to mimic its software role inside the vehicle. “These are providing opportunities for the automotive industry to reinvent itself; but the levels of encryption will be critical.”

Caviglioli highlighted the importance of building a ‘chain of trust’. This has to run from the initial design and the vehicle’s manufacture, to its sale through a dealership and continued via periodic diagnostics and maintenance (while accommodating changes of ownership) to final scrapping. “Security will need to be both by default and design, with the emphasis on protecting what matters, where it matters and when it matters,” she continued, emphasising the need for the protection of the contained data in a car along the way.

The ownership issue, stressed Gravier, will become all the more relevant in an era when people will no longer be using individually-owned cars as all-purpose vehicles, but looking for the optimal mobility solution for each specific need – including the sharing of connected cars. These, he said, will include upgraded, existing vehicles as well as new ones coming fully equipped off the production lines. Aftermarket installation for connectivity will need to be carried out by reliable companies.

There will also need to be clear protocols for the sharing of, and creating value from, the data generated by and collected from connected cars while out on the roads, with implications for its long-term management and security.

Related Content

  • May 10, 2019
    SafeRide: it’s time to act on cyberattacks
    Cyber threats are increasing rapidly and conventional security measures are unable to keep up. Ben Spencer talks to SafeRide’s Gil Reiter about what OEMs can do now As more vehicles become connected, so the potential threats to their security increase. Gil Reiter, vice president of product management for security firm SafeRide, says the biggest ‘attack surface’ for connected cars is their internet connectivity - and the in-vehicle applications that use the internet connection. “The most vulnerable co
  • September 4, 2018
    Irdeto security expert: ‘Think maliciously to beat hackers’
    Increased connectivity in transportation is a potential goldmine for hackers. To stop them, Stacy Janes at Irdeto says it’s important to think ‘maliciously’. Adam Hill talks to him about ITS’s weak points – and why turning up car radios could be enough to bring auto manufacturers to their knees
  • August 4, 2016
    Jeep hackers return to remotely hack Cherokee’s digital systems
    Just a year after they caused Chrysler to recall 1.4 million Jeep Cherokee vehicles after showing how they could remotely hijack a jeep’s digital systems over the internet, Charlie Miller and Chris Valasek are back to show how it could get worse. In the 2015 attack, they first toyed with the vehicle’s air conditioning, entertainment system and windscreen wipers, before cutting the transmission and causing the jeep to slowly come to a halt. At the Black Hat USA 2016 conference this week the two automot
  • September 15, 2023
    Software is at heart of safe vehicle connectivity, says Qt Group
    Connected vehicle safety isn’t just under threat from malicious actors exploiting code – it’s also about avoiding software faults that could result in harm to people, says Patrick Shelly of Qt Group