Safety for drivers and passengers has played a major role in vehicle development for decades. Passive and active safety systems such as seat belts, ABS or electronic stability control systems are now indispensable in every vehicle.
Legal frameworks such as ISO 26262 as well as established processes and tool chains exist that ensure the development and production of safe vehicles.
What changes with the introduction of networked, partially autonomous or fully autonomous vehicles?
Automotive Security: Requirements for Software Solutions Increase
Until just a few years ago, vehicles were largely closed systems with a manageable share of software functionality. Software was mostly installed on isolated control units and was only accessible via cable connection with specialized diagnostic tools. A software update was the exception.
Today, vehicle functions are increasingly realized entirely in software, which furthermore requires the interaction and communication between multiple sensors and control units. The number of interfaces to the environment, to smartphones, cloud systems or other vehicles is increasing – often even “wireless” via WLAN, Bluetooth and similar technologies. Software updates are becoming the rule rather than the exception.
With these changes, secure software and secure communication in the vehicle are becoming increasingly relevant. Automotive Security becomes a necessary engineering discipline.
Safety: A Matter of Risk
The assessment of safety, in technical, economic or private environments, is always a risk assessment. Possible damage cases are evaluated in combination with the associated probability of occurrence. High damage is only acceptable if it occurs with a very low probability.
The risk of failure of safety-relevant vehicle functions, such as the loss of braking function or the defect of an airbag sensor, can be described sufficiently well via statistical functions and experience values. Methods such as Failure Mode and Effects Analysis (FMEA) or Fault Tree Analysis (FTA) can subsequently quantify risks reliably. Additionally, proven measures to reduce safety risks exist, such as the redundant design of functions and components or the use of components with lower failure probability.
As a consequence of the widespread adoption of software-based vehicle functions, these rules no longer apply to the field of Automotive Security. And this in multiple respects:
A vulnerability in the system can be deliberately exploited multiple times by an attacker – in extreme cases in thousands of vehicles simultaneously. Making a statistical statement about the probability of damage occurring becomes impossible as a result. The situation is further complicated by the fact that a forecast of the probable behavior of attackers is also not possible. Attacks can occur without recognizable benefit for the attacker. The technical possibility of an attack or the existence of a vulnerability is sufficient for carrying out an attack.
- Multiple Damage Categories
Attackers can influence the safety of drivers and passengers – for example through manipulation of the braking function or deactivation of the airbag. In this case, the Security damage case corresponds to the damage considered in Safety analysis.
In Automotive Security assessment, however, additional damage categories come into play. Legal consequences can result from the loss of data worthy of protection. Personal data and data protection play a major role here. Monetary damage can be the direct result of data theft. For example, an attacker can obtain passwords, credit card data or control over the entire vehicle. Control over important vehicle functions can be the starting point for extortion scenarios against drivers or manufacturers.
The goal of Safety is simple to describe: the protection of the physical integrity of passengers.
A state that is safe for humans (Safe State) can often be achieved by shutting down functions that can no longer be controlled, up to and including stopping the vehicle.
From a Security perspective, however, a non-fully functional vehicle is a damage case to be avoided. Open doors and windows may protect the occupants – but they also facilitate the manipulation or theft of data or the entire vehicle.
Goal conflicts arise that must be taken into account from the definition of Safety and Security requirements, throughout the entire development process and up to the operation of the vehicle.
Although there are intersections between Safety and Security, the points mentioned above make clear the necessity for a procedurally and methodologically differentiated approach to Automotive Security. Some of the greatest challenges include:
Raising awareness among all organizational units involved in vehicle development in the value chain: Damage caused by Security deficiencies is often novel and not obvious. For example, violations of data protection regulations alone can result in penalties in the billions for manufacturers in the automotive industry. No department and no supplier can ignore this.
Building Security Expertise: The analysis and assessment of Automotive Security is a demanding task that requires not only Security know-how but also comprehensive understanding of the vehicle development process. Only simultaneous consideration of requirements, design, architecture and implementation leads to secure vehicles.
Establishing Automotive Security Processes: In addition to the standard “ISO-SAE 21424 Road Vehicles – Cybersecurity Engineering” still under development, with adoption expected no earlier than early 2020, organizations must become familiar with existing Security best practice approaches and apply them.
Selection and Implementation of Methods and Tools for Security Analysis and Assessment: New analysis methods and software tools are needed that meet complex Security requirements. Cross-departmental collaboration between experts from different disciplines plays an important role in this.
Particularly in the area of methods and tools, itemis can make a contribution to the successful implementation of Security. Software development, tool building, modeling and tracing in the automotive environment are part of itemis’s DNA.
itemis has acquired Security expertise in research and customer projects as well as through close collaboration with the Fraunhofer Institute for Applied and Integrated Security (AISEC). More will be reported shortly about itemis SECURE, a model-based tool for Security analysis and assessment.
Cyber Security at itemis — Systematic security engineering for automotive, IoT and Industry 4.0: Cyber Security →