SAE Cybersecurity Standards Activity

Slides:



Advertisements
Similar presentations
The International Security Standard
Advertisements

AASHTO Subcommittee on Maintenance Vehicle Communication Standards, Issues, & Potential Solutions July 19, 2011.
IHRA-ITS UN-ECE WP.29 ITS Informal Group Geneva, March, 2013 Overview of International Activities to Limit Distraction Document No. ITS (21st ITS,
Cyber Security and the Smart Grid George W. Arnold, Eng.Sc.D. National Institute of Standards and Technology (NIST) U.S. Department of Commerce
Halifax, 31 Oct – 3 Nov 2011ICT Accessibility For All ETSI Standardization Activities on M2M communications Joachim Koss, ETSI Board Member Document No:
Standards for Shared ICT Jeju, 13 – 16 May 2013 Gale Lightfoot Senior Staff Program Manager, Office of the CTO, SPB Cisco ATIS Cybersecurity Standards.
NHTSA Cyber Security Best Practices Study Tim Weisenberger December 7, 2011.
BITS Proprietary and Confidential © BITS Security and Technology Risks: Risk Mitigation Activities of US Financial Institutions John Carlson Senior.
Jeju, 13 – 16 May 2013Standards for Shared ICT CYBERSECURITY-RELATED STANDARDS ACTIVITY IN THE TELECOMMUNICATIONS INDUSTRY ASSOCIATION Eric Barnhart, Fellow.
Developing PC-Based Automobile Diagnostic System Based on OBD System Authors : Hu Jie, Yan Fuwu, Tian Jing, Wang Pan, Cao Kai School of Automotive Engineer.
1 Configuration Management “The Cookbook Approach”
Status Report for Critical Infrastructure Protection Advisory Group
Machine Health and Condition Based Maintenance Mark N. Pope, General Motors.
Jeju, 13 – 16 May 2013Standards for Shared ICT TIA TR-50 M2M-Smart Device Communications Dr. Jeffery Smith Chief Innovation and Technology Officer/EVP.
1 Automotive industry Reducing Noise Emissions from Motor Vehicles: New EU Commission legislative proposal World Forum on Vehicle Regulations (WP.29) 156.
January 2016 Lisa Boran Ford Motor Company SAE J3061 Committee Chair
SAE and Technical Policy Analysis Shuvo Bhattacharjee ETAS Inc. – Diagnostic Systems
I/M Solutions Conference
I/M Solutions 2011 Training Forum for Jurisdictions May 17, 2011 SAE J Recommended Practice Overview Bob Gruszczynski, OBD Specialist Volkswagen.
Standards Certification Education & Training Publishing Conferences & Exhibits 1 Copyright © ISA, All Rights reserved ISA99 - Industrial Automation and.
I/M Testing and Vehicle Communications. Drew Tech Background Products used for OEM Engineering, Diagnostics, End of Line testing, recall programs, and.
Connected Cars & Autonomous Vehicles
Status report on the activities of TF-CS/OTA
Quality Management System Deliverable Software 9115 revision A Key changes presentation IAQG 9115 Team March 2017.
IEEE ITS and Related Standardization Activities
MEM Cybersecurity Working Group Update to PCD Technical Committee
Eric Peirano, Ph.D., TECHNOFI, COO
Security of In-Vehicle Software
Outcome TFCS-05 // May OICA, Paris
Electric Vehicles Safety Global Technical Regulation
MEM Cybersecurity Working Group Update to PCD Technical Committee
Status report on the activities of TF-CS/OTA
Initial project results: Annex 6 – 20 Sept 2016
ICT & Environment Activities in Korea
ASSET - Automotive Software cyber SEcuriTy
CYBERSECURITY FOR AUTONOMOUS VEHICLES
Reinhard Scholl Deputy to the Director,
ETSI Standardization Activities on M2M communications
Outcome TFCS-11// February Washington DC
© 2016 Global Market Insights, Inc. USA. All Rights Reserved Automotive Cybersecurity Market to reach $837.1mn by 2024: Global Market.
SAE DSRC Technical Committee work and outlook
Mar 27, 2018 Mafijul Islam.
Sell the organization it is our ADVANTAGE
Michael Nawrocki, Vice President of Technology and Solutions ATIS
Copyright © SAE International
Electrical wiring harness interoperability: functionalities of AP242 ed2; preparation of the STEP 'electrical' Implementer Forum By Sophie Hérail (CIMPA.
Improving Vehicle Cybersecurity: ICT Industry Experience & Perspectives Denis Niles Senior Mobile & IoT Security Specialist Wireless Devices & Applications.
Val Shuman GSC ITS Task Force Chair
ISO/TC 204 Status Report Dick Schnacke, ISO/TC 204 Chairman March 2018
SAE J3016 Revisions & SAE Ads/adas Standards
Emerging Policy Issues Nanotechnologies and manufactured nanomaterials
An Urgent National Imperative
Connected & Automated Vehicle Executive Leadership Team (CAV ELT)
Status report on the activities of TF-CS/OTA
Recent developments in the EU transport policy
The SAFERtec project on V2I security assurance: concept and vision
Replies by the Task Force to the comments provided by GRVA members
ETSI Standardization Activities on Smart Grids
Mandate & Outputs expected for 2004
TIA TR-50 M2M-Smart Device Communications
Cyber Security ISA 99 / IEC D14 DLC-Meet, Jan 2019.
ISO and ISO/TC22 Overview March 2019
DSC Contract Management Committee Meeting
Adrian Guan, ISO/TC 204 Committee Manager
Informal document GRSG Rev.1
Alliance for Telecommunications Industry Solutions (ATIS) Update
CRYPTA LABS in collaboration with
DSC Contract Management Committee Meeting
A proposal for approach to proceed work in Cybersecurity TF
Access to data requirementS
Presentation transcript:

SAE Cybersecurity Standards Activity ETI ToolTech 2017 New Orleans, LA April 27, 2017

Car Hacking in the News… ToolTech 2017

But The Good News… ToolTech 2017

The Automobile is an Incredibly Complex Environment ToolTech 2017

SAE Publishes the World’s First Automotive Cybersecurity Standard J3061 Cybersecurity Guidebook for Cyber-Physical Automotive Systems Published January 2016; drive to a risk-based, process-driven approach to address the Cybersecurity threats the automotive environment is experiencing. Provides guidance on how to integrate cybersecurity into their product development life- cycle Establishes the desired relationships between cybersecurity and safety J3061 provides a foundation for further security standards development and is the “go-to” resource throughout industry ToolTech 2017

SAE Vehicle Cybersecurity Portfolio WIPs J3061-1 Automotive Cybersecurity Integrity Levels Develops an objective cybersecurity classification scheme J3061-2 Security Testing Methods Provides a detailed breakdown of currently available software and hardware security testing methods. J3061-3 Security Testing Tools This document serves as an agnostic list of manufacturers of security related tools and their capabilities. J3101 Requirements for Hardware-Protected Security for Ground Vehicle Applications Defines a common set of requirements for security to be implemented in hardware for ground vehicles to facilitate security enhanced applications and hardware protection for ground vehicle applications ToolTech 2017 6

SAE-ISO Automotive Cybersecurity Engineering Joint Work Group SAE-ISO Automotive Cybersecurity Engineering JWG Committee Co-Convenors: Lisa Boran, Ford, SAE Gido-Scharfenberger-Fabian, Carmeq, ISO Risk Management Project Team Product Development Project Team Operations Maintenance and Other Processes Project Team Process Overview and Inter-dependencies Project Team JWG Participation from: 11 ISO Nations 11 SAE experts Over 100 Project Team Participants from : 10 OEMs 11 major suppliers Dozens of consultants, security firms, and other suppliers ToolTech 2017

SAE Cybersecurity Activities J3061 is becoming a “go-to” resource for many SAE Committees in different discipline areas, e.g. On-Road Automated Driving Committee Vehicle Electrical and Electronics Diagnostics Committee Truck and Bus Controls and Communications Network Committee New Data Link Connector Vehicle Security Committee ToolTech 2017 8

Acute Focus on OBDII Security scenario hacker attack hacker attack over the mobile communication to the OBD dongle hacker starts critical functions over the UDS protocol September 12: Letter from House Committee on Energy and Commerce to NHTSA RE: OBD-II Security “…request that NHTA convene an industry-wide effort to develop a plan of action for addressing the risk posed by the existence of the OBD-II port in the modern vehicle ecosystem.” Courtesy of Bob Gruszczynski, Volkswagen: SAE September OBD Symposium September 2016 ToolTech 2017

SAE Convenes Industry to Address OBD-II Security SAE hosted invitation-only industry workshops December 1, 2016 and January 30, 2017. Goals: Identify common issues, needs, and approach to secure the OBD Gain buy-in to development of an accelerated standards approach Launch a new Standard Very well-attended by industry Leads: Mark Zachos, DGTech and Bob Gruszczynski, VW OEMS, Light Vehicle Suppliers, Heavy Manufacturers and Suppliers, and Auto-ISAC Associations: MEMA, ETI, AutoCare Association Government/Regulators: CARB, NHTSA, NIST ToolTech 2017

New Data Link Connector Vehicle Security Committee New Standard Work Item: J3138- Guidance for Securing the Data Link Connector (DLC) Goal: This document provides guidelines for securing communications with any off-board device for vehicles. Scope: The Data Link Connector supports communication of diagnostic information to off-board devices as well as legislated diagnostic information. This standard is focused on the securing the DLC in Vehicle network environments including: Open access to communication busses Communication busses isolated via a gateway  Any “hybrid” approaches ToolTech 2017

Data Link Connector Vehicle Security Committee: New Work Item Vehicle Interface Security Information Report Rationale: Other standards projects, mostly in ISO TC22 and TC204, aimed at securing the totality of interface to the vehicle (h/w and s/w interfaces). We want to learn from other activities and integrate as we can into future SAE Standards (and potentially joint standards with ISO). Proposed Scope: Provide an overview of some current practices which could be utilized for securing the vehicle’s interfaces from cybersecurity risks Samples: ISO Extended vehicle methodology (ExVe) ISO Vehicle Station Gateway (VSG) ISO Secure Vehicle Interface (SVI) ToolTech 2017

Other Cybersecurity Collaborations Working with NIST to examine Assurance testing for cybersecurity using NIST Cyber-Physical System Framework and Federated Test Bed Software testing suite Early collaboration with UN Economic Commission for Europe (UNECE) Working Party 29 Task Force on Automotive Cybersecurity and Over-The- Air Updates ToolTech 2017

Tim Weisenberger Contact: Tim.Weisenberger@sae.org Ph: 248.840.2106 ToolTech 2017