SAE Update - July 2021 - 18

FOCUS:
CYBERSECURITY
SUPERCHARGING vehicle cybersecurity
provide a reference and overview
of current best practices that are
used for securing the DLC from
cybersecurity threats when
unsecured external devices are
attached. Such external devices
may include external test
equipment (e.g., diagnostic scan
tools), remotely connected
applications (e.g., telematics
devices commonly used by
insurance companies), other
wireless connectivity devices, or
other unknown devices. As many
researchers are aware, some
DLCs on older-model-year
vehicles may have direct,
unrestricted access to one or
more critical in-vehicle networks
vulnerable to cybersecurity
threats.
The practices outlined in the
SAE documents are examples of
secure in-vehicle diagnostic
connectivity methods that are
considered acceptable for use in
the automotive industry. There
are several key data-securityrelated
items to consider when
interfacing to a vehicle. It is also
very important that the
transmission and storage of data
be secure and controlled against
outside access.
* Data should be sufficiently
secure (confidentiality and
18
July 2021
integrity) when stored and transmitted so that only
the intended recipient or target system is able to
receive and/or access it. All incoming
communications are treated as unsecure until
validated.
* The system should be able to withstand receiving
corrupt, invalid, or malicious data or commands via
its external and internal interfaces while still
remaining available for its primary use by an
authorized and validated user.
Then, after a new vehicle is delivered to a customer,
there are additional cybersecurity use cases for:
authorized dealer servicing, authorized independent
third-party servicing/repair facilities, owner servicing,
access by law enforcement, access by first responders
and emergency personnel, and end-of-life access by
recycling facilities that must disable, reset, or deploy
hazardous items. In each of these cases, varying levels
of access and length of authorization access periods
(time) may be required. Plus, a secure IT infrastructure
to manage the issuance and revocation of secure
access keys/credentials must be established.
recommended Practice SAE J3005
In 1996, the state of California mandated that all
vehicles come equipped with a diagnostic port to
diagnose emission systems. Soon, the diagnostic port
was standard on all vehicles and adopted for other
diagnostic purposes.
However, it also became an outlet for other plug-in
devices, such as insurance companies placing " good
driver " devices in the port to monitor the driving
habits of its customers. Other enterprising companies
may, for example, create devices that stream
information to a cellphone or monitor a vehicle's
UPDATE

SAE Update - July 2021

Table of Contents for the Digital Edition of SAE Update - July 2021

SAE Update - July 2021 - Cov1
SAE Update - July 2021 - Cov2
SAE Update - July 2021 - Cov3
SAE Update - July 2021 - 1
SAE Update - July 2021 - 2
SAE Update - July 2021 - 3
SAE Update - July 2021 - 4
SAE Update - July 2021 - 5
SAE Update - July 2021 - 6
SAE Update - July 2021 - 7
SAE Update - July 2021 - 8
SAE Update - July 2021 - 9
SAE Update - July 2021 - 10
SAE Update - July 2021 - 11
SAE Update - July 2021 - 12
SAE Update - July 2021 - 13
SAE Update - July 2021 - 14
SAE Update - July 2021 - 15
SAE Update - July 2021 - 16
SAE Update - July 2021 - 17
SAE Update - July 2021 - 18
SAE Update - July 2021 - 19
SAE Update - July 2021 - 20
SAE Update - July 2021 - 21
SAE Update - July 2021 - 22
SAE Update - July 2021 - 23
SAE Update - July 2021 - 24
SAE Update - July 2021 - 25
SAE Update - July 2021 - 26
SAE Update - July 2021 - 27
SAE Update - July 2021 - 28
SAE Update - July 2021 - 29
SAE Update - July 2021 - 30
SAE Update - July 2021 - 31
SAE Update - July 2021 - 32
SAE Update - July 2021 - 33
SAE Update - July 2021 - 34
SAE Update - July 2021 - 35
SAE Update - July 2021 - 36
SAE Update - July 2021 - 37
SAE Update - July 2021 - 38
SAE Update - July 2021 - 39
SAE Update - July 2021 - 40
SAE Update - July 2021 - 41
SAE Update - July 2021 - 42
SAE Update - July 2021 - 43
SAE Update - July 2021 - 44
SAE Update - July 2021 - 45
SAE Update - July 2021 - 46
SAE Update - July 2021 - 47
https://www.nxtbook.com/smg/sae/24UPD07
https://www.nxtbook.com/smg/sae/24UPD06
https://www.nxtbook.com/smg/sae/24UPD05
https://www.nxtbook.com/smg/sae/24UPD04
https://www.nxtbook.com/smg/sae/24UPD03
https://www.nxtbook.com/smg/sae/24UPD02
https://www.nxtbook.com/smg/sae/24UPD01
https://www.nxtbook.com/smg/sae/23UPD12
https://www.nxtbook.com/smg/sae/23UPD11
https://www.nxtbook.com/smg/sae/23UPD10
https://www.nxtbook.com/smg/sae/23UPD09
https://www.nxtbook.com/smg/sae/23UPD08
https://www.nxtbook.com/smg/sae/23UPD07
https://www.nxtbook.com/smg/sae/23UPD06
https://www.nxtbook.com/smg/sae/23UPD05
https://www.nxtbook.com/smg/sae/23UPD04
https://www.nxtbook.com/smg/sae/23UPD03
https://www.nxtbook.com/smg/sae/23UPD02
https://www.nxtbook.com/smg/sae/23UPD01
https://www.nxtbook.com/smg/sae/22UPD12
https://www.nxtbook.com/smg/sae/22UPD11
https://www.nxtbook.com/smg/sae/22UPD10
https://www.nxtbook.com/smg/sae/22UPD09
https://www.nxtbook.com/smg/sae/22UPD08
https://www.nxtbook.com/smg/sae/22UPD07
https://www.nxtbook.com/smg/sae/22UPD06
https://www.nxtbook.com/smg/sae/22UPD05
https://www.nxtbook.com/smg/sae/22UPD04
https://www.nxtbook.com/smg/sae/22UPD03
https://www.nxtbook.com/smg/sae/22UPD02
https://www.nxtbook.com/smg/sae/22UPD01
https://www.nxtbook.com/smg/sae/21UPD12
https://www.nxtbook.com/smg/sae/21UPD11
https://www.nxtbook.com/smg/sae/21UPD10
https://www.nxtbook.com/smg/sae/21UPD09
https://www.nxtbook.com/smg/sae/21UPD08
https://www.nxtbook.com/smg/sae/21UPD07
https://www.nxtbook.com/smg/sae/21UPD06
https://www.nxtbook.com/smg/sae/21UPD05
https://www.nxtbook.com/smg/sae/21UPD04
https://www.nxtbook.com/smg/sae/21UPD03
https://www.nxtbook.com/smg/sae/21UPD02
https://www.nxtbookmedia.com