Cybersecurity of Firmware Updates

Over-the-Air (OTA) software and firmware updates are widely considered essential for networked devices. In the automotive industry, OTA firmware updates are anticipated to increase the efficiency and decrease the time in updating the critical firmware in vehicles’ electronic control units (ECUs). This project had these objectives: understand the scope and relevant attributes of firmware updates, understand their vulnerabilities and update solutions, understand mitigation methods for those vulnerabilities, and learn from adjacent industries. The report first presents a literature and technology review of the state-of-the-art of software updates in industries related to automotive, including the commercial aviation, medical, and consumer electronics industries. Next it identifies and assesses software update functionality risks in current and near-term future automobiles. Finally, it reviews mitigation methods to address those risks. In addition, this report describes the SAE AS5553A voluntary standard for the detection of and protection against counterfeit electronic parts in the aerospace industry and how it relates to the automotive industry.

  • Record URL:
  • Corporate Authors:

    University of Michigan Transportation Research Institute

    2901 Baxter Road
    Ann Arbor, MI  United States  48109-2150

    Volkswagen Group of America, Herndorn

    ,    

    National Highway Traffic Safety Administration

    1200 New Jersey Avenue, SE
    Washington, DC  United States  20590
  • Authors:
    • Bielawski, Russ
    • Gaynier, Ron
    • Ma, Di
    • Lauzon, Sam
    • Weimerskirch, André
  • Publication Date: 2020-10

Language

  • English

Media Info

  • Media Type: Digital/other
  • Edition: Final Report
  • Features: Figures; References; Tables;
  • Pagination: 103p

Subject/Index Terms

Filing Info

  • Accession Number: 01774114
  • Record Type: Publication
  • Report/Paper Numbers: DOT HS 812 807
  • Contract Numbers: DTNH22-15-R-00104 Vehicle Electronics Systems Safe
  • Files: HSL, NTL, TRIS, ATRI, USDOT
  • Created Date: Jun 14 2021 9:29AM