Home
Scholarly Works
Safe and Secure Automotive Over-the-Air Updates
Conference

Safe and Secure Automotive Over-the-Air Updates

Abstract

Over-the-air updates have been used for years in the software industry, allowing bug fixes and enhancements to desktop, laptop, and mobile operating systems and applications. Automotive vehicles now depend on software to the extent that manufacturers are turning to over-the-air updates for critical vehicle functionality. History shows that our software systems are most vulnerable to lapses in safety and dependability when they undergo change, and performing an update over a communication channel adds a significant security concern. This paper presents our ideas on assuring integrated safety and security of over-the-air updates through assurance case templates that comply with both ISO 26262 (functional safety) and SAE J3061 (cyber-security). Wisely, the authors of SAE J3061 structured the guidebook so that it meshes well with ISO 26262, and we have been able to use principles we developed for deriving an assurance case template from ISO 26262, to help include compliance with SAE J3061 in the template. The paper also demonstrates how a specialization of the template helps guide us to pre-emptively mitigate against potential vulnerabilities in over-the-air update implementations.

Authors

Chowdhury T; Lesiuta E; Rikley K; Lin C-W; Kang E; Kim B; Shiraishi S; Lawford M; Wassyng A

Series

Lecture Notes in Computer Science

Volume

11088

Pagination

pp. 172-187

Publisher

Springer Nature

Publication Date

January 1, 2018

DOI

10.1007/978-3-319-99130-6_12

Conference proceedings

Lecture Notes in Computer Science

ISSN

0302-9743
View published work (Non-McMaster Users)

Contact the Experts team