R2C_KeyVisuals_eTruck_Car_1660x680.jpg

Cybersecurity

Philosophy

The 3 pillars of end-to-end security in automotive cybersecurity

In the rapidly evolving landscape of automotive technology, cybersecurity has become a critical focus. Ensuring the safety and cybersecurity of vehicles requires a comprehensive approach that encompasses prevention, detection, and response, all underpinned by robust governance. Here is how AUMOVIO is approaching these three pillars:

  

Cybersecurity_3pillars_1400x764v2.jpg

Prevention is the first line of defense in automotive cybersecurity. It involves implementing measures to protect vehicles from potential cyber threats before they can cause harm in the field. Our key strategies include:

  

  • Security by design: integrating security features into the vehicle's design from the outset, ensuring that every component and system is built with security in mind. Development cycle complaint to internal standards such as ISO/SAE 21434 which includes continuous vulnerability scanning.
  • Access control: restricting access to critical systems and data to authorized persons only, using techniques such as encryption, multi-factor authentication, real-time prevention techniques.
  • Proper testing: using state-of-the-art cybersecurity testing methodologies as part of our Validation and Verification measures to identify weaknesses to the earliest time possible.

Despite the best preventive measures, threats and attack vectors might appear over time which require defense measures in the field. Detection involves monitoring systems to identify these threats asquickly as possible. Key components include:

  

  • Continuous Monitoring: Continuously watching vehicle systems and networks to detect threats in real-time.
  • Intrusion Detection System (IDS): Functionality on the vehicles to monitor in vehicle networks on suspicious activity and alert vehicle manufacturers or fleet operators..
  • Anomaly Detection: Using artificial intelligence (AI) to identify unusual patterns of behavior that may indicate a cyber-attack.

When a threat is detected, a swift and effective response is crucial to mitigate its impact. In this pillar we focus on:

  

  • Incident response playbooks: predefined procedures for responding to different types of cyber incidents, ensuring a coordinated and efficient reaction.
  • Forensic analysis: investigating the cause and extent of a breach to understand how it occurred and prevent future incidents.
  • Ad-hoc OTA updates: keeping software and firmware up to date to protect against known vulnerabilities and emerging threats.

Underlying these three pillars is our Cybersecurity Management System (CSMS), which provides our framework for managing product cybersecurity across the entire life cycle of our products and services. Our effective governance involves:

  

  • Policy development: establishing clear policies and standards for product cybersecurity along the whole product life cycle.
  • Threat analysis & risk assessment (TARA): identifying, assessing and prioritizing risks to ensure that resources are allocated effectively to address the most significant threats.
  • Compliance: ensuring that all product cybersecurity measures comply with relevant laws, regulations, and industry standards, especially the automotive cybersecurity leading standard ISO/SAE 21434 that we are certified for.

By integrating these three pillars – prevent, detect and respond – within a strong governance framework, we as AUMOVIO can better protect our products and services the vehicles build out of them from cyber threats and ensure the safety, security, privacy of drivers and passengers alike.

Security approach and products

5 layers of cybersecurity

In today's interconnected world, ensuring robust cybersecurity is paramount. Our comprehensive product cybersecurity approach is built on the foundation of the "5 layers of cybersecurity", each designed to protect different aspects of our products and operations. These layers work in harmony to provide a multi-faceted defense against potential threats.

Use cases

Our suite of cybersecurity solutions is designed to protect against unauthorized access, cyberattacks and malware. We provide robust ECU and network protection to ensure the safe and secure operation of vehicle systems. Our anomaly detection capabilities swiftly identify potential ransomware attacks, alerting our vehicle security operation center (vSOC) for immediate action.

  

Advanced privacy system helps to protect the data from the user insides the vehicles. Additionally, our secure over-the-air (OTA) update system delivers firmware upgrades with strong encryption and authentication, responding promptly to any issues that arise.

ECU and  network protection icon

ECU and

network protection

Ransomware with anomaly detection  and reporting to VSOC icon

Ransomware with anomaly detection

and reporting to VSOC

Secure OTA update responding  with update on the issue icon

Secure OTA update responding

with update on the issue

Collaboration

Cybersecurity is a team-sport

With our subsidiaries PlaxidityX (PX) and Elektrobit (EB), AUMOVIO is offering holistic cybersecurity solutions portfolio to cover all aspects for secure and connected vehicles.

PlaxidityX keyvisual

PlaxidityX  is a global automotive cybersecurity leader, trusted by OEMs to protect over 72 million vehicles. It provides DevSecOps, vehicle protection and fleet protection technologies and services for automotive and mobility manufacturers. PlaxidityX’s solutions ensure that vehicle components, networks, and fleets are secured and compliant throughout their life cycle.

Elektrobit SDV keyvisual

Elektrobit  provides safe and secure operating system solution (e.g. AUTOSAR, Linux) incl. cryptographical solutions.

  

  

  

  

Contact

Do you want to know more?

The contact form is temporarily unavailable due to scheduled maintenance. It will be restored soon.

*If the contact form does not load, please check the advanced cookie settings and activate the functional cookies for the purpose of contact management.