DC25_SLIDES_Drive_MovingTowardsSoftwareDefinedVehicles_Bernabeu.pdf
1、Page 1 GlobalPlatform 2025|Confidential Moving Towards Software Defined Vehicles:Cybersecurity&Standardization29thJanuary 2025Gil Bernabeu,CTO GlobalPlatformPage 2https:/ 3 SAE/ISO 21434 Cybersecurity Management Systems ISO/PAS 5112:2022 Road vehicles Guidelines for auditing cybersecurity engineerin
2、g SAE J3101 Hardware Protected Security Environments for Ground Vehicles UNECE 155 Cybersecurity Management Systems(CSMS)ISO/FIDS 20489 Software Update Management System(SUMS)UNECE 156 Software Update Management System(SUMS)National&EU Cybersecurity ActsNHTSA Cybersecurity GuidelinesEuropean Cyber R
3、esilience Act(CRA)EU Radio Equipment Directive 2014/53/EU(RED)Privacy-e.g.GDPRRight to Repair RegulationsSoftware bill of materials(SBOM)Cybersecurity Multi-NationalAutomotive REgulationsRegulations Impacting Automotive from Other DomainsPage 4Challenges of Automotive Security Market TodayLack of Cl
4、ear Metrics on Security RobustnessDevice Identification And UpdateFragmentation of Secure Boot RequirementsLack of Incremental Build Upon Solutions(each new service requires a new ECU)Difficulty in managing trust over extended value chain with new service providers(beyond OEMs)Proprietary Applicatio
5、n Ecosystem Proprietary Key Lifecycle Management(Provisioning And Decommissioning)Proprietary Implementation of CryptographyVendor Lock-InLack of Clear Metrics on Security RobustnessDevice Identification And UpdateFragmentation of Secure Boot RequirementsLack of Incremental Build Upon Solutions(each
6、 new service requires a new ECU)Difficulty in managing trust over extended value chain with new service providers(beyond OEMs)Page 5More Attack VectorsMore Attack TypesMore Attack SurfacesMore Types of HackersMore Security Riskhttps:/ Architectures,New Services,New PlayersPage 6https:/ 7High Value o





点击查看更多