SAE Update - December 2021 - 27

ENGINEEERING
EVENTS
are becoming more sophisticated.
" The lack of maturity is baked into things
like our industry standards, " he said.
" We've got things like [SAE] J1939 that is
fundamentally not secure. You can send a
command to the engine or the transmission
requesting more torque, and it's very
simple to do and it's published. "
The issue spreads throughout the entire
supply chain.
" Things that we can do as product
developers are limited by the
microprocessors we have to work with and
their capabilities, " York said. " And there's
only a handful of micros that all of us can
use that are suitable for an automotive
environment, particularly on engine. So,
getting things that have the cryptocapability
and resources to do the things
that you need to do are challenging. It's
coming along - the things that we're
developing today are a lot better than the
things we had 10 years ago. "
" Remote attacks and attacks at scale "
are what keeps York awake at night, he
said. " If you can shut down an entire fleet
or an entire brand of telematics, that would
be a Colonial Pipeline type of thing. "
Attackers chain things together, so
physical access could initiate a snowball
effect, York explained: " You can learn
things with physical access and then go
find a vulnerability in a telematics system
that lets you get access to the truck and
CAN to send messages that cause an ECU
to stop working or reset. And then if you've
UPDATE
got a vulnerability in the wireless carrier
that allows you to enumerate the serial
numbers of all the vehicles, then you can
scale it. "
Electric and autonomous trucks will have
a lot more electronic controllers and
networks.
" There are more operating systems
involved probably than there have been in
the past; therefore, there's more variety of
networks, " York said. " So, we might have
CAN and CAN FD and Ethernet or LIN all
turning up on a vehicle. As the vehicle gets
more complicated, it does increase the
attack surface and the old adage that
'security is only as strong as its weakest
link' is very true. "
York noted that engine manufacturers in
the recent past placed all their engineering
energy on meeting increasingly stricter
emissions regulations; cybersecurity efforts
took a back seat.
" We have to spend a lot of time squirting
fuel, to get the emissions just right, " he
said. " The treadmill that we were on for a
long time with the vehicle electronics was
pretty challenging for all of us, and
cybersecurity [suffered]. "
Industry standards must evolve and
provide a better platform for addressing
advanced technologies and vehicles, York
said.
Click here to read a longer version of this
article by SAE's editor-in-chief of Truck and
Off-Highway Engineering magazine, Ryan
Gehm. n
December 2021
27
https://www.sae.org/news/2021/10/defending-the-heavy-vehicle-cyber-domain

SAE Update - December 2021

Table of Contents for the Digital Edition of SAE Update - December 2021

SAE Update - December 2021 - Cov1
SAE Update - December 2021 - Cov2
SAE Update - December 2021 - 1
SAE Update - December 2021 - 2
SAE Update - December 2021 - 3
SAE Update - December 2021 - 4
SAE Update - December 2021 - 5
SAE Update - December 2021 - 6
SAE Update - December 2021 - 7
SAE Update - December 2021 - 8
SAE Update - December 2021 - 9
SAE Update - December 2021 - 10
SAE Update - December 2021 - 11
SAE Update - December 2021 - 12
SAE Update - December 2021 - 13
SAE Update - December 2021 - 14
SAE Update - December 2021 - 15
SAE Update - December 2021 - 16
SAE Update - December 2021 - 17
SAE Update - December 2021 - 18
SAE Update - December 2021 - 19
SAE Update - December 2021 - 20
SAE Update - December 2021 - 21
SAE Update - December 2021 - 22
SAE Update - December 2021 - 23
SAE Update - December 2021 - 24
SAE Update - December 2021 - 25
SAE Update - December 2021 - 26
SAE Update - December 2021 - 27
SAE Update - December 2021 - 28
SAE Update - December 2021 - 29
SAE Update - December 2021 - 30
SAE Update - December 2021 - 31
SAE Update - December 2021 - 32
SAE Update - December 2021 - 33
SAE Update - December 2021 - 34
https://www.nxtbook.com/smg/sae/25UPD01
https://www.nxtbook.com/smg/sae/24UPD12
https://www.nxtbook.com/smg/sae/24UPD11
https://www.nxtbook.com/smg/sae/24UPD10
https://www.nxtbook.com/smg/sae/24UPD09
https://www.nxtbook.com/smg/sae/24UPD08
https://www.nxtbook.com/smg/sae/24UPD07
https://www.nxtbook.com/smg/sae/24UPD06
https://www.nxtbook.com/smg/sae/24UPD05
https://www.nxtbook.com/smg/sae/24UPD04
https://www.nxtbook.com/smg/sae/24UPD03
https://www.nxtbook.com/smg/sae/24UPD02
https://www.nxtbook.com/smg/sae/24UPD01
https://www.nxtbook.com/smg/sae/23UPD12
https://www.nxtbook.com/smg/sae/23UPD11
https://www.nxtbook.com/smg/sae/23UPD10
https://www.nxtbook.com/smg/sae/23UPD09
https://www.nxtbook.com/smg/sae/23UPD08
https://www.nxtbook.com/smg/sae/23UPD07
https://www.nxtbook.com/smg/sae/23UPD06
https://www.nxtbook.com/smg/sae/23UPD05
https://www.nxtbook.com/smg/sae/23UPD04
https://www.nxtbook.com/smg/sae/23UPD03
https://www.nxtbook.com/smg/sae/23UPD02
https://www.nxtbook.com/smg/sae/23UPD01
https://www.nxtbook.com/smg/sae/22UPD12
https://www.nxtbook.com/smg/sae/22UPD11
https://www.nxtbook.com/smg/sae/22UPD10
https://www.nxtbook.com/smg/sae/22UPD09
https://www.nxtbook.com/smg/sae/22UPD08
https://www.nxtbook.com/smg/sae/22UPD07
https://www.nxtbook.com/smg/sae/22UPD06
https://www.nxtbook.com/smg/sae/22UPD05
https://www.nxtbook.com/smg/sae/22UPD04
https://www.nxtbook.com/smg/sae/22UPD03
https://www.nxtbook.com/smg/sae/22UPD02
https://www.nxtbook.com/smg/sae/22UPD01
https://www.nxtbook.com/smg/sae/21UPD12
https://www.nxtbook.com/smg/sae/21UPD11
https://www.nxtbook.com/smg/sae/21UPD10
https://www.nxtbook.com/smg/sae/21UPD09
https://www.nxtbook.com/smg/sae/21UPD08
https://www.nxtbook.com/smg/sae/21UPD07
https://www.nxtbook.com/smg/sae/21UPD06
https://www.nxtbook.com/smg/sae/21UPD05
https://www.nxtbook.com/smg/sae/21UPD04
https://www.nxtbook.com/smg/sae/21UPD03
https://www.nxtbook.com/smg/sae/21UPD02
https://www.nxtbookmedia.com