SAE Update - July 2021 - 22

FOCUS:
CYBERSECURITY
SUPERCHARGING vehicle cybersecurity
performance and functionality of
these connected systems.
One common maintenance
action for a vehicle is to utilize
the diagnostics interface to
update the firmware for an ECU.
This action involves connecting a
diagnostic computer (typically a
laptop PC) to a vehicle
diagnostics adapter (VDA)
device. The PC software
communicates via the VDA to
identify the vehicle's ECU eligible
for the firmware update. Before
initiating an ECU firmware
action, the diagnostics computer
device will often send a request
via the internet to the
manufacturer/supplier of the
ECU to determine if there is new
firmware available.
One of the biggest challenges
of detecting an intrusion is
classifying any unintended code
embedded into the firmware
being uploaded to the ECU. This
is a challenge because the
machine code itself is unknown
and potentially unique for every
ECU. Therefore, many rule-based
anomaly-detection systems will
not be able to distinguish a good
firmware image from a malicious
one by inspection alone. This
means that an on-vehicle
intrusion-detection system must
22
July 2021
TestCUBE2
Simulator
USB Cable
- CAN 1 Ch.
DTS Monaco 8
and TestCUBE2
Software
running on
WIN10 Laptop
DPA5 via
Bluetooth
USB Dongle
- CAN 1 Ch.
System test bench used to verify test SAE J3138 recommendations.
be designed to allow for these updates to occur but
limit the effect of a particular ECU from being
attacked and becoming " rogue. " To confound the
issue, the firmware is often considered to be
proprietary, which makes testing and validation of an
intrusion detection of a firmware reflashing process
even harder.
Prior to running an SAE J3138 test on actual
vehicles, a simulated test on a lab bench can be
performed in order to verify the test design rules. The
picture shown above describes the bench setup of
the test.
If the vehicle response to the tool request indicates
that the vehicle is not in a safe state (i.e., conditions
not correct), the service request aborts and the
vehicle test sequence is not executed. However, a
defect/malicious actor could try to trick the test (for
example, by injecting a false vehicle speed of zero
before the actual vehicle speed message) thereby
tricking (spoofing) the test to continue. Vehicle safe
UPDATE

SAE Update - July 2021

Table of Contents for the Digital Edition of SAE Update - July 2021

SAE Update - July 2021 - Cov1
SAE Update - July 2021 - Cov2
SAE Update - July 2021 - Cov3
SAE Update - July 2021 - 1
SAE Update - July 2021 - 2
SAE Update - July 2021 - 3
SAE Update - July 2021 - 4
SAE Update - July 2021 - 5
SAE Update - July 2021 - 6
SAE Update - July 2021 - 7
SAE Update - July 2021 - 8
SAE Update - July 2021 - 9
SAE Update - July 2021 - 10
SAE Update - July 2021 - 11
SAE Update - July 2021 - 12
SAE Update - July 2021 - 13
SAE Update - July 2021 - 14
SAE Update - July 2021 - 15
SAE Update - July 2021 - 16
SAE Update - July 2021 - 17
SAE Update - July 2021 - 18
SAE Update - July 2021 - 19
SAE Update - July 2021 - 20
SAE Update - July 2021 - 21
SAE Update - July 2021 - 22
SAE Update - July 2021 - 23
SAE Update - July 2021 - 24
SAE Update - July 2021 - 25
SAE Update - July 2021 - 26
SAE Update - July 2021 - 27
SAE Update - July 2021 - 28
SAE Update - July 2021 - 29
SAE Update - July 2021 - 30
SAE Update - July 2021 - 31
SAE Update - July 2021 - 32
SAE Update - July 2021 - 33
SAE Update - July 2021 - 34
SAE Update - July 2021 - 35
SAE Update - July 2021 - 36
SAE Update - July 2021 - 37
SAE Update - July 2021 - 38
SAE Update - July 2021 - 39
SAE Update - July 2021 - 40
SAE Update - July 2021 - 41
SAE Update - July 2021 - 42
SAE Update - July 2021 - 43
SAE Update - July 2021 - 44
SAE Update - July 2021 - 45
SAE Update - July 2021 - 46
SAE Update - July 2021 - 47
https://www.nxtbook.com/smg/sae/24UPD07
https://www.nxtbook.com/smg/sae/24UPD06
https://www.nxtbook.com/smg/sae/24UPD05
https://www.nxtbook.com/smg/sae/24UPD04
https://www.nxtbook.com/smg/sae/24UPD03
https://www.nxtbook.com/smg/sae/24UPD02
https://www.nxtbook.com/smg/sae/24UPD01
https://www.nxtbook.com/smg/sae/23UPD12
https://www.nxtbook.com/smg/sae/23UPD11
https://www.nxtbook.com/smg/sae/23UPD10
https://www.nxtbook.com/smg/sae/23UPD09
https://www.nxtbook.com/smg/sae/23UPD08
https://www.nxtbook.com/smg/sae/23UPD07
https://www.nxtbook.com/smg/sae/23UPD06
https://www.nxtbook.com/smg/sae/23UPD05
https://www.nxtbook.com/smg/sae/23UPD04
https://www.nxtbook.com/smg/sae/23UPD03
https://www.nxtbook.com/smg/sae/23UPD02
https://www.nxtbook.com/smg/sae/23UPD01
https://www.nxtbook.com/smg/sae/22UPD12
https://www.nxtbook.com/smg/sae/22UPD11
https://www.nxtbook.com/smg/sae/22UPD10
https://www.nxtbook.com/smg/sae/22UPD09
https://www.nxtbook.com/smg/sae/22UPD08
https://www.nxtbook.com/smg/sae/22UPD07
https://www.nxtbook.com/smg/sae/22UPD06
https://www.nxtbook.com/smg/sae/22UPD05
https://www.nxtbook.com/smg/sae/22UPD04
https://www.nxtbook.com/smg/sae/22UPD03
https://www.nxtbook.com/smg/sae/22UPD02
https://www.nxtbook.com/smg/sae/22UPD01
https://www.nxtbook.com/smg/sae/21UPD12
https://www.nxtbook.com/smg/sae/21UPD11
https://www.nxtbook.com/smg/sae/21UPD10
https://www.nxtbook.com/smg/sae/21UPD09
https://www.nxtbook.com/smg/sae/21UPD08
https://www.nxtbook.com/smg/sae/21UPD07
https://www.nxtbook.com/smg/sae/21UPD06
https://www.nxtbook.com/smg/sae/21UPD05
https://www.nxtbook.com/smg/sae/21UPD04
https://www.nxtbook.com/smg/sae/21UPD03
https://www.nxtbook.com/smg/sae/21UPD02
https://www.nxtbookmedia.com