The automotive industry is undergoing an evolution from traditional cars that use mechanical devices to software-defined vehicles (SDVs) that use software platforms to control the performance of the vehicles. Software-defined vehicles have different layers of software and cloud connections, and this has enabled the industry to realize advanced technology such as autonomous cars. However, with this technology, there are emerging cybersecurity challenges that need to be taken into account.
For a broader market perspective, see the Software-Defined Vehicle Market analysis.
Expanding Attack Surface in Connected Vehicles
One of the most significant challenges that the cybersecurity field faces in the SDV environment is the rapid growth in the attack surface. In the modern vehicle, connectivity solutions such as cellular networks, Wi-Fi, Bluetooth, and vehicle-to-everything communication are becoming more popular. While these connectivity solutions provide a greater vehicle experience for the driver, they also provide a number of different avenues that could be exploited by a hacker.
In the traditional vehicle, electronic control units were isolated from external connections. In SDV, a centralized computing platform is the primary method for connecting to external networks and the cloud. Each software interface, application programming interface, or connected service that is introduced into the SDV potentially represents a number of different vulnerabilities that could be exploited by a hacker. In the modern vehicle, as the vehicle becomes more connected, the hacker will attempt to exploit these vulnerabilities to gain access to the vehicle’s systems.
Risks Associated with Over-the-Air Updates
Software updates over the air are a vital feature of software-defined vehicles because it allows for the provision of new features, security patches, and performance updates. However, the update mechanism can be a potential entry point for cybersecurity risks if not well-protected. The attackers may target the intercepted packages of the software updates. If the compromised software is installed in the vehicle, it can alter its operation or introduce backdoors for attacks.
Therefore, it is vital to ensure authentication, encryption, and integrity checks in the software update over the air update mechanism. The automaker must also develop an effective rollout strategy to ensure that the packages of the software updates are validated and tested before the rollout process.
Legacy System Vulnerabilities
Another issue arises from the integration of old automobile communication protocols with modern digital communication. Old automobile communication protocols, such as CAN or LIN, are not secure since they were not originally intended to be used in a network with security as an issue.
