SlideShare a Scribd company logo
S
Global Automotive Practice
Automotive Cyber Security, October 2020
AGENDA
Copyright© Strategy Analytics, Inc. 2
OUR APPROACHES AT A GLANCE
Automotive Cyber
Security
• Attack Surfaces
• Regulations and Standards
• Industry Challenges
• Software Development Trends Survey
• Collaboration
• What GENIVI Offers
WIRELESS CONNECTIVITY IN CARS
MANY ATTACK SURFACES
3
0
20,000
40,000
60,000
80,000
100,000
120,000
2018 2019 2020 2021 2022 2023 2024 2025 2026 2027
Units
in
000s
Bluetooth Embedded Cellular Wifi
• The cumulative number of
cars shipped with
embedded cellular
connectivity will total
570M vehicles between
2018 and 2027.
• Cars with Bluetooth make
up an even larger number
at 808M, cumulative,
shipped vehicles sold
between 2018 and 2027.
• Cars with Wi-Fi will total
520M cumulative units
shipped between 2018 and
2027.
REGULATIONS AND STANDARDS SET THE STAGE
4
On June 25, 2020, the UNECE announced it had formally adopted two new sets of regulations
as part of the broader WP.29 regulations. These new regulations include:
• UN Regulation on Cybersecurity and Cyber Security Management Systems
• UN Regulation on Software Updates and Software Updates Management Systems
In nations that follow these regulations (e.g. EU members, Japan, Republic of Korea, etc.),
automakers selling cars for these markets must have certain capabilities in place to monitor,
detect, mitigate, and ultimately fix vulnerabilities in cars that malicious actors could
compromise.
54 countries are signatories to the 1958 UNECE agreement, and are likely to adopt these
regulations at some point in the future, though many plan to do so in the near term.
Key Dates:
• These new regulations will apply as of January 2021.
• The EU plans to make these regulations mandatory for all new vehicle types from July 2022,
and for all new vehicles from July, 2024.
• Japan adopted these regulations for SAE Level 3 vehicles in April, 2020, and plans to adopt
it for all OTA update-capable vehicles as of November, 2020.
• The Republic of Korea plans to implement the regulation at a currently undecided future
date.
Other Regulations/Standards/Guidelines:
Standards:
• ISO 21434 (Road Vehicles – Cybersecurity Engineering,
draft)
• ISO 24089 (Software Updates)
• SAE J3101 (Hardware Protected Security)
• SAE J3061 (Cybersecurity Guidebook for Cyber-Physical
Vehicle Systems)
• AUTOSAR (Secure On Board Communications)
Other National Legislation/Guidelines:
EU
• GDPR
U.S.
• NHTSA Cyber Security Guidelines
• Proposed legislation (SELF DRIVE Act, AV Start Act)
• California - CCPA
China
• Cybersecurity Law
• Encryption Law (draft)
• SAC/TC114/SC34 (related to AV and Intelligent
vehicles; has a cyber security working group)
INDUSTRY CHALLENGES
5
The automotive industry is facing numerous challenges related to cyber security and must
work to implement a range of processes and technologies in a short timeframe.
• Compliance: For global OEMs, developing the processes and systems to document
compliance with the WP.29 UN Regulation on Cybersecurity and Cyber Security
Management Systems is going to be critical over the next few years.
• Software Asset Tracking: OEMs must start using systems that provide an inventory of,
and monitor, all the software running in each ECU in every deployed vehicle on roads.
• Operations: OEMs must either develop or expand the capabilities of internal teams that
will be actively monitoring fleets for cyber security threats and analyzing, and fixing (or
mitigating) existing vulnerabilities.
• Balancing Current and Next-Generation E/E Architecture Requirements: Although some
OEMs are able to move to next-gen E/E architectures over the next few years, not all
OEMs are moving at the same speed, and many will need to support legacy platforms for
years to come. But to comply with regulatory requirements, OEMs MUST secure those
legacy platforms, otherwise in many markets they simply won’t be able to sell cars.
SOFTWARE DEVELOPMENT TRENDS
6
6%
6%
39%
33%
I don't know Less than 5%
10-25% Over 25%
The survey: Developed in partnership with Aurora Labs, Strategy Analytics
collected survey responses between July 21st and August 10th, 2020.
Respondents included professionals working for automakers (22%), Tier 1s
(21%), software vendors (15%), semiconductor vendors (15%), industry
analysts (13%), and representatives of companies that don’t fall into those
categories (“Other.,” 14%). You can download the survey results here.
(Top right) What percentage of vehicle software will be developed in-house
by mass-market automotive manufacturers by 2025?
Automaker representative respondents (22%, or 41 individuals) most
strongly supported the “Over 25%” category, indicating their intent to do
more software development in-house over the next few years.
Total Number of Respondents: 220
(Bottom right) Do you expect this trend to increase over time?
The majority of respondents said they believed this trend would continue.
Total Number of Respondents: 205
76%
24%
Yes No
SOFTWARE DEVELOPMENT TRENDS
7
How many different suppliers have
their code in a high-end vehicle?
Currently, software for high-end
vehicles comes from a wide range of
sources. The majority of respondents
believe (77%) believe that a minimum
of 10 different suppliers are providing
software for the average high-end car,
and 52% of respondents said a
minimum of 25 different suppliers are
involved. From a cyber security
perspective, this means it’s challenging
for OEMs to even track what software
is in their cars and whether any of that
software has existing vulnerabilities.
Total Number of Respondents: 211
9%
14%
25%
24%
28%
I don't know Less than 10 10 to 25 25 to 40 Over 50
SOFTWARE DEVELOPMENT TRENDS
8
9%
26%
25%
24%
I don't know Car year model 2024 Car year model 2027 Later than 2027
When do you expect more than 1
million vehicles per year, across the
globe, to be produced with more
powerful domain controller-based E/E
architectures?
Automotive OEM respondents were the
most polarized in their respondents,
reflecting that some plan to move very
quickly whereas others plan to use
legacy platforms for a number of years
to come. 52% of respondents believe
that the shift will occur for 2027-MY
vehicles or later.
Total Number of Respondents: 209
SOFTWARE DEVELOPMENT TRENDS
9
12%
19%
26%
36%
The user experience (zero downtime)
The overall cost of the solution (to the manufacturer)
The safety and redundancy of the solution
The security of the solution
In your opinion, what is the most
important for vehicle manufacturers
with regard to OTA updates?
The largest group of respondents said
“security” for OTA was the most
important to OEMs, though safety (at
26%) was a close second. Since safety
and security, in this case, are closely
linked, these responses indicate that
the industry believes it is focused on
reducing the potential for problems to
occur, either those caused by bad
actors or those caused by poor design
decisions, mistakes, and process-
related issues.
Total Number of Respondents: 193
SOFTWARE DEVELOPMENT TRENDS
10
18%
40%
42%
No, regulations will not speed deployment
Yes, regulating OTA safety and security will accelerate deployment
I am not aware of new regulations for OTA updates
Do you think the newly adopted
regulation on Software Update
Management Systems (UNECE WP.29)
will accelerate the deployment of OTA
updates beyond the infotainment
system?
The survey was global, and since the
regulations won’t apply in every region,
there’s no surprise that a percentage
were not aware of the new WP.29
regulations related to OTA updates. Of
those who were aware, the more than
double (at 40% of respondents) said
they thought having regulations would
speed up deployment.
Total Number of Respondents: 190
COLLABORATION
11
Challenges
• Regulations, e.g. UNECE WP.29, will require companies to collaborate more than ever before to find, mitigate or fix
vulnerabilities that could expose vehicle systems to cyber attacks.
• Fewer vehicles are selling due to COVID 19 and the current economic downturn (though sales forecasts for 2021
show improvements in sales volumes)
• The need to shift to EV powertrains and move forward with autonomous vehicle technologies.
• Managing vehicle connectivity on a large-scale basis, including large, fleet-wide OTA updates.
What is GENIVI doing to help the industry meet these challenges?
• GENIVI provides the opportunity to collaborate, specifically with the goal of helping to create tools and solutions
that companies can implement.
• “GENIVI doesn't want to just create best practices and standards if nobody uses them. We'll do the hard work,
[companies in the industry] need to implement them.”
• The GENIVI Security Team is open to industry professionals from across the industry, and is one of the GENIVI groups
that doesn’t require participants to be GENIVI members.
• One example project is OpenXSAM, which is a data output scheme for threats and events and is working towards
compliance for ISO21434 and UNECE WP.29 requirements. Project partners include GENIVI Security Team,
Automotive Security Research Group (ASRG), Block Harbor Cyber Security, SecForCars, and itemis’ Security Analysis
Team.
Current Team Lead :
Joby Jester -- joby.jester@irdeto.com
Focused on Actionable Automotive Security Through Industry
Collaboration.
How We’re Different:
• Supported by a Diverse Group of Experts, We Tackle the Day-
to-Day Security Concerns of the Industry. Inside and Outside
of the Vehicle.
• We Use Thought Leadership to Bring Digested Information
and Updates on the Ever-Growing Complexity of the
Automotive Security Space
Reasons to Join:
• Friendly, Accepting Networking Environment
• Ability to Work on Content and/or Speaking Opportunities
• Build Portfolio of Knowledge from Working With Experts
For Links to all Past Content and
Meeting Notices :
https://at.projects.genivi.org/wiki/
Please Subscribe to The Security
Team Mailing List:
https://lists.genivi.org/

More Related Content

Similar to Strategy Analytics - Automotive Cyber Security - Oct 2020.pptx

Automotive Cybersecurity: Shifting into Overdrive
Automotive Cybersecurity: Shifting into OverdriveAutomotive Cybersecurity: Shifting into Overdrive
Automotive Cybersecurity: Shifting into Overdrive
accenture
 
Webinar: CX up AND costs down?
Webinar: CX up AND costs down?Webinar: CX up AND costs down?
Webinar: CX up AND costs down?
The Digital Insurer
 
Fortify Continuous Delivery
Fortify Continuous DeliveryFortify Continuous Delivery
Fortify Continuous Delivery
Mainstay
 
Car Cybersecurity: The Gap Still Exists
Car Cybersecurity: The Gap Still ExistsCar Cybersecurity: The Gap Still Exists
Car Cybersecurity: The Gap Still Exists
Security Innovation
 
ConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WPConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WP
Greg Harms
 
V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11
V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11
V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11
coachdave
 
FASTR_Overview2017
FASTR_Overview2017FASTR_Overview2017
FASTR_Overview2017
Craig Hurst
 
Security Architecture for Cyber Physical Systems
Security Architecture for Cyber Physical SystemsSecurity Architecture for Cyber Physical Systems
Security Architecture for Cyber Physical Systems
Alan Tatourian
 
Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...
Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...
Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...
RAKESH RANA
 
Intelligence on the Intractable Problem of Software Security
Intelligence on the Intractable Problem of Software SecurityIntelligence on the Intractable Problem of Software Security
Intelligence on the Intractable Problem of Software Security
Tyler Shields
 
Achieving Software Safety, Security, and Reliability Part 2
Achieving Software Safety, Security, and Reliability Part 2Achieving Software Safety, Security, and Reliability Part 2
Achieving Software Safety, Security, and Reliability Part 2
Perforce
 
Pitch Deck Teardown: Nokod Security's $8M Seed deck
Pitch Deck Teardown: Nokod Security's $8M Seed deckPitch Deck Teardown: Nokod Security's $8M Seed deck
Pitch Deck Teardown: Nokod Security's $8M Seed deck
HajeJanKamps
 
Software Pricing and Licensing Survey Results and 2012 Predictions
Software Pricing and Licensing Survey Results and 2012 PredictionsSoftware Pricing and Licensing Survey Results and 2012 Predictions
Software Pricing and Licensing Survey Results and 2012 Predictions
Flexera
 
Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...
Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...
Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...
TechSci Research
 
Video analytics market
Video analytics marketVideo analytics market
Video analytics market
ameliasimon0
 
Retail Industry Application Security Survey Insights
Retail Industry Application Security Survey InsightsRetail Industry Application Security Survey Insights
Retail Industry Application Security Survey Insights
Veracode
 
Driving Risks Out of Embedded Automotive Software
Driving Risks Out of Embedded Automotive SoftwareDriving Risks Out of Embedded Automotive Software
Driving Risks Out of Embedded Automotive Software
Parasoft
 
DOES14 - Joshua Corman - Sonatype
DOES14 - Joshua Corman - SonatypeDOES14 - Joshua Corman - Sonatype
DOES14 - Joshua Corman - Sonatype
Gene Kim
 
“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...
“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...
“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...
Edge AI and Vision Alliance
 
The 10 most advanced automotive tech companies of 2020
The 10 most advanced automotive tech companies of 2020The 10 most advanced automotive tech companies of 2020
The 10 most advanced automotive tech companies of 2020
Mirror Review
 

Similar to Strategy Analytics - Automotive Cyber Security - Oct 2020.pptx (20)

Automotive Cybersecurity: Shifting into Overdrive
Automotive Cybersecurity: Shifting into OverdriveAutomotive Cybersecurity: Shifting into Overdrive
Automotive Cybersecurity: Shifting into Overdrive
 
Webinar: CX up AND costs down?
Webinar: CX up AND costs down?Webinar: CX up AND costs down?
Webinar: CX up AND costs down?
 
Fortify Continuous Delivery
Fortify Continuous DeliveryFortify Continuous Delivery
Fortify Continuous Delivery
 
Car Cybersecurity: The Gap Still Exists
Car Cybersecurity: The Gap Still ExistsCar Cybersecurity: The Gap Still Exists
Car Cybersecurity: The Gap Still Exists
 
ConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WPConnectedAutos-Kymeta-7498-WP
ConnectedAutos-Kymeta-7498-WP
 
V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11
V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11
V2 V V2 I Apps Come To Michigan Test Bed Article 9 1 11
 
FASTR_Overview2017
FASTR_Overview2017FASTR_Overview2017
FASTR_Overview2017
 
Security Architecture for Cyber Physical Systems
Security Architecture for Cyber Physical SystemsSecurity Architecture for Cyber Physical Systems
Security Architecture for Cyber Physical Systems
 
Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...
Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...
Increasing Efficiency of ISO 26262 Verification and Validation by Combining F...
 
Intelligence on the Intractable Problem of Software Security
Intelligence on the Intractable Problem of Software SecurityIntelligence on the Intractable Problem of Software Security
Intelligence on the Intractable Problem of Software Security
 
Achieving Software Safety, Security, and Reliability Part 2
Achieving Software Safety, Security, and Reliability Part 2Achieving Software Safety, Security, and Reliability Part 2
Achieving Software Safety, Security, and Reliability Part 2
 
Pitch Deck Teardown: Nokod Security's $8M Seed deck
Pitch Deck Teardown: Nokod Security's $8M Seed deckPitch Deck Teardown: Nokod Security's $8M Seed deck
Pitch Deck Teardown: Nokod Security's $8M Seed deck
 
Software Pricing and Licensing Survey Results and 2012 Predictions
Software Pricing and Licensing Survey Results and 2012 PredictionsSoftware Pricing and Licensing Survey Results and 2012 Predictions
Software Pricing and Licensing Survey Results and 2012 Predictions
 
Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...
Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...
Asia-Pacific Automotive Cybersecurity Market Size, Share & Analysis 2024 | Te...
 
Video analytics market
Video analytics marketVideo analytics market
Video analytics market
 
Retail Industry Application Security Survey Insights
Retail Industry Application Security Survey InsightsRetail Industry Application Security Survey Insights
Retail Industry Application Security Survey Insights
 
Driving Risks Out of Embedded Automotive Software
Driving Risks Out of Embedded Automotive SoftwareDriving Risks Out of Embedded Automotive Software
Driving Risks Out of Embedded Automotive Software
 
DOES14 - Joshua Corman - Sonatype
DOES14 - Joshua Corman - SonatypeDOES14 - Joshua Corman - Sonatype
DOES14 - Joshua Corman - Sonatype
 
“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...
“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...
“The Automotive Driver Monitoring Market: What’s Happening? Why? What’s the O...
 
The 10 most advanced automotive tech companies of 2020
The 10 most advanced automotive tech companies of 2020The 10 most advanced automotive tech companies of 2020
The 10 most advanced automotive tech companies of 2020
 

Recently uploaded

Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...
Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...
Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...
Motronix
 
The changed agenda in the global sourcing industry
The changed agenda in the global sourcing industryThe changed agenda in the global sourcing industry
The changed agenda in the global sourcing industry
Patrick Nickol
 
Saket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model Safe
Saket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model SafeSaket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model Safe
Saket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model Safe
tinakumariji156
 
欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】 .
欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】   .欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】   .
欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】 .
santoyobishop68
 
Generative AI - Unleashing the Power of Creativity with Machines​
Generative AI - Unleashing the Power of Creativity with Machines​Generative AI - Unleashing the Power of Creativity with Machines​
Generative AI - Unleashing the Power of Creativity with Machines​
Rahul Bhrambhatt
 
十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】 .
十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】      .十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】      .
十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】 .
giovannifabio834
 
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model SafeKarol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model Safe
khansayyad1256
 
Hyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill Climb
Hyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill ClimbHyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill Climb
Hyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill Climb
Hyundai Motor Group
 
For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...
For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...
For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...
bookhotbebes1
 
202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇
202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇
202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇
ffg01100
 
Power Metering Market Global Trends and Forecast Analysis (2023-2032)
Power Metering Market Global Trends and Forecast Analysis (2023-2032)Power Metering Market Global Trends and Forecast Analysis (2023-2032)
Power Metering Market Global Trends and Forecast Analysis (2023-2032)
PriyanshiSingh187645
 
RK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model Safe
RK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model SafeRK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model Safe
RK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model Safe
vasudha malikmonii$A17
 
Malviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model Safe
Malviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model SafeMalviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model Safe
Malviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model Safe
nissarali1987
 
Design of Automatic Car Washing System and Construct Prototype.pdf
Design of Automatic Car Washing System and Construct Prototype.pdfDesign of Automatic Car Washing System and Construct Prototype.pdf
Design of Automatic Car Washing System and Construct Prototype.pdf
rahulchaure14
 
This is ppt on m272 engine good knowledge about m272 engine this is good ...
This is ppt on m272 engine  good knowledge  about m272 engine  this is good  ...This is ppt on m272 engine  good knowledge  about m272 engine  this is good  ...
This is ppt on m272 engine good knowledge about m272 engine this is good ...
AvneetHaryana
 
International Journal of Microwave Engineering (JMICRO)
International Journal of Microwave Engineering (JMICRO)International Journal of Microwave Engineering (JMICRO)
International Journal of Microwave Engineering (JMICRO)
jmicro
 
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model SafeKarol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model Safe
dakshishsingh98798
 
Simple steps to perfectly adjust your car seat
Simple steps to perfectly adjust your car seatSimple steps to perfectly adjust your car seat
Simple steps to perfectly adjust your car seat
jennifermiller8137
 
1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf
1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf
1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf
CarlosAndresRiera
 
Polymer_Application_in_sbBpace[1]23.pptx
Polymer_Application_in_sbBpace[1]23.pptxPolymer_Application_in_sbBpace[1]23.pptx
Polymer_Application_in_sbBpace[1]23.pptx
harshyadav3563
 

Recently uploaded (20)

Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...
Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...
Expert Mercedes Car Clutch Services Smooth Gear Shifts and Enhanced Driving P...
 
The changed agenda in the global sourcing industry
The changed agenda in the global sourcing industryThe changed agenda in the global sourcing industry
The changed agenda in the global sourcing industry
 
Saket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model Safe
Saket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model SafeSaket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model Safe
Saket @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Jya Khan Top Model Safe
 
欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】 .
欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】   .欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】   .
欧洲杯比分-欧洲杯比分推荐-欧洲杯比分买球推荐 |【​网址​🎉ac10.net🎉​】 .
 
Generative AI - Unleashing the Power of Creativity with Machines​
Generative AI - Unleashing the Power of Creativity with Machines​Generative AI - Unleashing the Power of Creativity with Machines​
Generative AI - Unleashing the Power of Creativity with Machines​
 
十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】 .
十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】      .十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】      .
十大足球投注网站软件-足球投注网站的软件 |【​网址​🎉ac44.net🎉​】 .
 
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model SafeKarol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Ginni Singh Top Model Safe
 
Hyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill Climb
Hyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill ClimbHyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill Climb
Hyundai IONIQ 5 N TA’s debut at 2024 Pikes Peak International Hill Climb
 
For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...
For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...
For Better Ahmedabad #ℂall #Girl Service ❤ 0000000000 ❤ Hiii Thise is Neha Ro...
 
202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇
202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇
202554.com香蕉影视全网最高清,最新电影,最新电视剧,在线观看狐妖小红娘月红篇
 
Power Metering Market Global Trends and Forecast Analysis (2023-2032)
Power Metering Market Global Trends and Forecast Analysis (2023-2032)Power Metering Market Global Trends and Forecast Analysis (2023-2032)
Power Metering Market Global Trends and Forecast Analysis (2023-2032)
 
RK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model Safe
RK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model SafeRK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model Safe
RK Puram @ℂall @Girls ꧁❤ 9873777170 ❤꧂Fabulous sonam Mehra Top Model Safe
 
Malviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model Safe
Malviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model SafeMalviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model Safe
Malviya Nagar @ℂall @Girls ꧁❤ 9873940964 ❤꧂VIP Golu Mishra Top Model Safe
 
Design of Automatic Car Washing System and Construct Prototype.pdf
Design of Automatic Car Washing System and Construct Prototype.pdfDesign of Automatic Car Washing System and Construct Prototype.pdf
Design of Automatic Car Washing System and Construct Prototype.pdf
 
This is ppt on m272 engine good knowledge about m272 engine this is good ...
This is ppt on m272 engine  good knowledge  about m272 engine  this is good  ...This is ppt on m272 engine  good knowledge  about m272 engine  this is good  ...
This is ppt on m272 engine good knowledge about m272 engine this is good ...
 
International Journal of Microwave Engineering (JMICRO)
International Journal of Microwave Engineering (JMICRO)International Journal of Microwave Engineering (JMICRO)
International Journal of Microwave Engineering (JMICRO)
 
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model SafeKarol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model Safe
Karol Bagh @ℂall @Girls ꧁❤ 9873777170 ❤꧂VIP Neha Singla Top Model Safe
 
Simple steps to perfectly adjust your car seat
Simple steps to perfectly adjust your car seatSimple steps to perfectly adjust your car seat
Simple steps to perfectly adjust your car seat
 
1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf
1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf
1- Diagramas Electricos EcoSport 2010 Euro IV 08-2011.pdf
 
Polymer_Application_in_sbBpace[1]23.pptx
Polymer_Application_in_sbBpace[1]23.pptxPolymer_Application_in_sbBpace[1]23.pptx
Polymer_Application_in_sbBpace[1]23.pptx
 

Strategy Analytics - Automotive Cyber Security - Oct 2020.pptx

  • 1. S Global Automotive Practice Automotive Cyber Security, October 2020
  • 2. AGENDA Copyright© Strategy Analytics, Inc. 2 OUR APPROACHES AT A GLANCE Automotive Cyber Security • Attack Surfaces • Regulations and Standards • Industry Challenges • Software Development Trends Survey • Collaboration • What GENIVI Offers
  • 3. WIRELESS CONNECTIVITY IN CARS MANY ATTACK SURFACES 3 0 20,000 40,000 60,000 80,000 100,000 120,000 2018 2019 2020 2021 2022 2023 2024 2025 2026 2027 Units in 000s Bluetooth Embedded Cellular Wifi • The cumulative number of cars shipped with embedded cellular connectivity will total 570M vehicles between 2018 and 2027. • Cars with Bluetooth make up an even larger number at 808M, cumulative, shipped vehicles sold between 2018 and 2027. • Cars with Wi-Fi will total 520M cumulative units shipped between 2018 and 2027.
  • 4. REGULATIONS AND STANDARDS SET THE STAGE 4 On June 25, 2020, the UNECE announced it had formally adopted two new sets of regulations as part of the broader WP.29 regulations. These new regulations include: • UN Regulation on Cybersecurity and Cyber Security Management Systems • UN Regulation on Software Updates and Software Updates Management Systems In nations that follow these regulations (e.g. EU members, Japan, Republic of Korea, etc.), automakers selling cars for these markets must have certain capabilities in place to monitor, detect, mitigate, and ultimately fix vulnerabilities in cars that malicious actors could compromise. 54 countries are signatories to the 1958 UNECE agreement, and are likely to adopt these regulations at some point in the future, though many plan to do so in the near term. Key Dates: • These new regulations will apply as of January 2021. • The EU plans to make these regulations mandatory for all new vehicle types from July 2022, and for all new vehicles from July, 2024. • Japan adopted these regulations for SAE Level 3 vehicles in April, 2020, and plans to adopt it for all OTA update-capable vehicles as of November, 2020. • The Republic of Korea plans to implement the regulation at a currently undecided future date. Other Regulations/Standards/Guidelines: Standards: • ISO 21434 (Road Vehicles – Cybersecurity Engineering, draft) • ISO 24089 (Software Updates) • SAE J3101 (Hardware Protected Security) • SAE J3061 (Cybersecurity Guidebook for Cyber-Physical Vehicle Systems) • AUTOSAR (Secure On Board Communications) Other National Legislation/Guidelines: EU • GDPR U.S. • NHTSA Cyber Security Guidelines • Proposed legislation (SELF DRIVE Act, AV Start Act) • California - CCPA China • Cybersecurity Law • Encryption Law (draft) • SAC/TC114/SC34 (related to AV and Intelligent vehicles; has a cyber security working group)
  • 5. INDUSTRY CHALLENGES 5 The automotive industry is facing numerous challenges related to cyber security and must work to implement a range of processes and technologies in a short timeframe. • Compliance: For global OEMs, developing the processes and systems to document compliance with the WP.29 UN Regulation on Cybersecurity and Cyber Security Management Systems is going to be critical over the next few years. • Software Asset Tracking: OEMs must start using systems that provide an inventory of, and monitor, all the software running in each ECU in every deployed vehicle on roads. • Operations: OEMs must either develop or expand the capabilities of internal teams that will be actively monitoring fleets for cyber security threats and analyzing, and fixing (or mitigating) existing vulnerabilities. • Balancing Current and Next-Generation E/E Architecture Requirements: Although some OEMs are able to move to next-gen E/E architectures over the next few years, not all OEMs are moving at the same speed, and many will need to support legacy platforms for years to come. But to comply with regulatory requirements, OEMs MUST secure those legacy platforms, otherwise in many markets they simply won’t be able to sell cars.
  • 6. SOFTWARE DEVELOPMENT TRENDS 6 6% 6% 39% 33% I don't know Less than 5% 10-25% Over 25% The survey: Developed in partnership with Aurora Labs, Strategy Analytics collected survey responses between July 21st and August 10th, 2020. Respondents included professionals working for automakers (22%), Tier 1s (21%), software vendors (15%), semiconductor vendors (15%), industry analysts (13%), and representatives of companies that don’t fall into those categories (“Other.,” 14%). You can download the survey results here. (Top right) What percentage of vehicle software will be developed in-house by mass-market automotive manufacturers by 2025? Automaker representative respondents (22%, or 41 individuals) most strongly supported the “Over 25%” category, indicating their intent to do more software development in-house over the next few years. Total Number of Respondents: 220 (Bottom right) Do you expect this trend to increase over time? The majority of respondents said they believed this trend would continue. Total Number of Respondents: 205 76% 24% Yes No
  • 7. SOFTWARE DEVELOPMENT TRENDS 7 How many different suppliers have their code in a high-end vehicle? Currently, software for high-end vehicles comes from a wide range of sources. The majority of respondents believe (77%) believe that a minimum of 10 different suppliers are providing software for the average high-end car, and 52% of respondents said a minimum of 25 different suppliers are involved. From a cyber security perspective, this means it’s challenging for OEMs to even track what software is in their cars and whether any of that software has existing vulnerabilities. Total Number of Respondents: 211 9% 14% 25% 24% 28% I don't know Less than 10 10 to 25 25 to 40 Over 50
  • 8. SOFTWARE DEVELOPMENT TRENDS 8 9% 26% 25% 24% I don't know Car year model 2024 Car year model 2027 Later than 2027 When do you expect more than 1 million vehicles per year, across the globe, to be produced with more powerful domain controller-based E/E architectures? Automotive OEM respondents were the most polarized in their respondents, reflecting that some plan to move very quickly whereas others plan to use legacy platforms for a number of years to come. 52% of respondents believe that the shift will occur for 2027-MY vehicles or later. Total Number of Respondents: 209
  • 9. SOFTWARE DEVELOPMENT TRENDS 9 12% 19% 26% 36% The user experience (zero downtime) The overall cost of the solution (to the manufacturer) The safety and redundancy of the solution The security of the solution In your opinion, what is the most important for vehicle manufacturers with regard to OTA updates? The largest group of respondents said “security” for OTA was the most important to OEMs, though safety (at 26%) was a close second. Since safety and security, in this case, are closely linked, these responses indicate that the industry believes it is focused on reducing the potential for problems to occur, either those caused by bad actors or those caused by poor design decisions, mistakes, and process- related issues. Total Number of Respondents: 193
  • 10. SOFTWARE DEVELOPMENT TRENDS 10 18% 40% 42% No, regulations will not speed deployment Yes, regulating OTA safety and security will accelerate deployment I am not aware of new regulations for OTA updates Do you think the newly adopted regulation on Software Update Management Systems (UNECE WP.29) will accelerate the deployment of OTA updates beyond the infotainment system? The survey was global, and since the regulations won’t apply in every region, there’s no surprise that a percentage were not aware of the new WP.29 regulations related to OTA updates. Of those who were aware, the more than double (at 40% of respondents) said they thought having regulations would speed up deployment. Total Number of Respondents: 190
  • 11. COLLABORATION 11 Challenges • Regulations, e.g. UNECE WP.29, will require companies to collaborate more than ever before to find, mitigate or fix vulnerabilities that could expose vehicle systems to cyber attacks. • Fewer vehicles are selling due to COVID 19 and the current economic downturn (though sales forecasts for 2021 show improvements in sales volumes) • The need to shift to EV powertrains and move forward with autonomous vehicle technologies. • Managing vehicle connectivity on a large-scale basis, including large, fleet-wide OTA updates. What is GENIVI doing to help the industry meet these challenges? • GENIVI provides the opportunity to collaborate, specifically with the goal of helping to create tools and solutions that companies can implement. • “GENIVI doesn't want to just create best practices and standards if nobody uses them. We'll do the hard work, [companies in the industry] need to implement them.” • The GENIVI Security Team is open to industry professionals from across the industry, and is one of the GENIVI groups that doesn’t require participants to be GENIVI members. • One example project is OpenXSAM, which is a data output scheme for threats and events and is working towards compliance for ISO21434 and UNECE WP.29 requirements. Project partners include GENIVI Security Team, Automotive Security Research Group (ASRG), Block Harbor Cyber Security, SecForCars, and itemis’ Security Analysis Team.
  • 12. Current Team Lead : Joby Jester -- joby.jester@irdeto.com Focused on Actionable Automotive Security Through Industry Collaboration. How We’re Different: • Supported by a Diverse Group of Experts, We Tackle the Day- to-Day Security Concerns of the Industry. Inside and Outside of the Vehicle. • We Use Thought Leadership to Bring Digested Information and Updates on the Ever-Growing Complexity of the Automotive Security Space Reasons to Join: • Friendly, Accepting Networking Environment • Ability to Work on Content and/or Speaking Opportunities • Build Portfolio of Knowledge from Working With Experts For Links to all Past Content and Meeting Notices : https://at.projects.genivi.org/wiki/ Please Subscribe to The Security Team Mailing List: https://lists.genivi.org/

Editor's Notes

  1. Hundreds of millions of wireless attack surfaces. This slide drives home the expansion in the number wireless attack surfaces and shows the need to take security seriously.
  2. WP.29 involves threat analysis, testing, verifying security pre-production, then post-sale involves monitoring, mitigation, and remediation if an attack occurs or if the OEM discoveres a vulnerability.