6 CONCLUSIONS
This paper outlined a realistic case to keep a vehicle
secure for its lifecycle. Privacy and security threats
for OTA updates were analyzed with the aim to
inform discussions on long-term support threats and
relevant tools.
We observed that outcomes of state of the art
methods are useful and complement each other. Yet,
our experience shows that the used methods still lack
application guidelines and templates appropriate for
threat modeling of automotive systems. Future
research can address these gaps.
ACKNOWLEDGEMENTS
This work is supported by the H2020-ECSEL
programme of the European Commission; grant no.
783119, SECREDAS project. Teun Hendriks made
valuable remarks on an earlier paper version.
REFERENCES
FASTR, 2018, Automotive Industry Guidelines for Secure
Over-the-Air Updates, April 2018
Idrees, Sabir & Schweppe, Hendrik & Roudier, Yves &
Wolf, Marko & Scheuermann, Dirk & Henniger, Olaf.
2011. Secure Automotive On-Board Protocols: A Case
of Over-the-Air Firmware Updates. pp. 224-238.
ISO12207, 2017. International Organization for
standardization, ISO/IEC/IEEE 12207:2017, Systems
and software engineering -- Software life cycle
processes, https://www.iso.org/standard/63712.html.
Last accessed: Jan 2019.
ISO26262, 2011, 26262: Road vehicles-Functional safety.
International Standard ISO/FDIS 26262
Kim, Wuyts, Joosen, Wouter, 2015 LINDDUN privacy
threat modeling: a tutorial.
Lewis, Derek Lane, 2010, Over-the-air vehicle systems
updating and associate security protocols, patent
US9464905B2, priority date: 2010-06-25
Ma Z., Schmittner, C., 2016, Threat Modeling for
Automotive Security Analysis, SecTech 2016, 2016
Macher, Georg, Armengaud, Eric, Brenner, Eugen,
Kreiner, Christian, 2016, Threat and Risk Assessment
Methodologies in the Automotive Domain, Procedia
Computer Science, Volume 83, 2016, Pp. 1288-1294,
Miller, C. Valasek, C., 2015, Remote exploitation of an
unaltered passenger vehicle, August 2015, available:
http://illmatics.com/Remote%20Car%20Hacking.pdf,
last accessed: Jan 2019
Nccgroup, 2017, Automotive threat modeling template,
https://github.com/nccgroup/The_Automotive_Threat_
Modeling_Template, last accessed: Jan 2019.
O'Kane S., 2018, Tesla can change so much with over-the-
air updates that it’s messing with some owners’ heads,
https://www.theverge.com/2018/6/2/17413732/tesla-
over-the-air-software-updates-brakes, acc.: Jan 2019.
Papadimitratos, P., Buttyan, L., Holczer, T., Schoch, E.,
Freudiger, J., Raya, M., Ma, Z., Kargl, F., Kung, A.,
Hubaux, J.-P., 2008, Secure Vehicular Communication
Systems: Design and Architecture, IEEE Communi-
cations Magazine, vol. 46, no. 11, pp. 100--109,
November 2008
SAE, 2016, Vehicle Electrical System Security Committee.
SAE J3061-Security Guidebook for Cyber-Physical
Automotive Systems.
Schmidt, Silvie & Tausig, Mathias & Koschuch, Manuel &
Hudler, Matthias & Simhandl, Georg & Puddu, Patrick
& Stojkovic, Zoran, 2018, How Little is Enough?
Implementation and Evaluation of a Lightweight
Secure Firmware Update Process for the Internet of
Things. 10.5220/0006670300630072.
Schmittner, C., Ma, Z., Reyes, C., Dillinger, O., Puschner,
P., 2016, Using SAE J3061 for automotive security
requirement engineering, In International Conference
on Computer Safety, Reliability, and Security, pp. 157-
170. Springer International Publishing, 2016
Schmittner, C., Ma, Z., Gruber, T., 2015, Combining Safety
and Security Engineering for Trustworthy Cyber-
Physical Systems, ERCIM News 2015(102)
Steger, M., Karner, M., Hillebrand, J., Rom, W., Boano C.,
and Römer, K., 2016, Generic framework enabling
secure and efficient automotive wireless SW updates,
IEEE 21st International Conference on Emerging
Technologies and Factory Automation (ETFA), Berlin,
pp. 1-8.
Tesla, 2019, Vehicle Warranty, https://www.tesla.com/
support/vehicle-warranty, last accessed: Jan 2019.
UNECE, 2018, Draft Recommendation on Software
Updates of the Task Force on Cyber Security and Over-
the-air issues of UNECE WP.29 IWG ITS/AD.
https://www.unece.org/fileadmin/DAM/trans/doc/2018
/wp29grva/GRVA-01-17.pdf, accessed: Jan 2019.
Van Huynh Le, Jerry den Hartog, Nicola Zannone, 2018,
Security and privacy for innovative automotive
applications: A survey, Computer Communications,
Volume 132, 2018, Pages 17-41, ISSN 0140-3664.
Practical Security and Privacy Threat Analysis in the Automotive Domain: Long Term Support Scenario for Over-the-Air Updates
555