Status report on the activities of TF-CS/OTA

Slides:



Advertisements
Similar presentations
Transmitted by the representative of JAPAN Toward Realization of the “Mutual Recognition of International Whole Vehicle Type Approval (IWVTA)” under the.
Advertisements

T.Russell Shields, Co-Chair, Collaboration on ITS Communication Standards Martin Adolph, Programme Coordinator, ITU ITU activities on secure vehicle software.
Common Understanding on Major Horizontal Issues and Legal Obstacles Excerpts from the relevant sections of the ToR: II. Working items to be covered (details.
FIA MOBILITY & TOURISM Gerd Preuss, FIA Representative at UNECE, WP 29 Protection Against Mileage Fraud Current Status in ITS-AD 110 th GRSG Meeting Geneva,
Status report on the activities of TF-CS/OTA
Suggestion for Summarizing Process of the Principles
Outcome TFCS-05 // May OICA, Paris
Co-Sponsors: China, Japan, EU and US 59th Session GRSP May 9-13, 2016
Status report on the activities of TF-CS/OTA
Common Understanding on Major Horizontal Issues and Legal Obstacles
30-31, August 2017 Den Hague, Netherlands)
Main problems of NL proposal for UN Software Regulation
Case studies on software update
OICA input on software updates to UN TF CS/OTA
Submitted by the expert form Japan Document No. ITS/AD-09-12
Chair: Jin Seop Park, Republic of Korea Secretary: Thomas Kinsky, OICA
Concept of ACSF TAN (Type Approval Number)
Outcome TFCS-04 // March ITU, Geneva
Suggestion on software update
Outcome TFCS-07 // August NH Den Haag, NL
UN Task Force on Cyber Security and OTA issues
Outcome TFCS-11// February Washington DC
Status report on the activities of TF-CS/OTA
Electric Vehicles and the Environment (EVE IWG)
Outcome TFCS-11// February Washington DC
Proposal for Next Actions - Based on Threats Table Approach -
Final Report of TF-CS/OTA September The Amba Hotel, London
Outcome of TFCS-12 - summary slides - (detailed meeting minutes will be provided separately) April The Shilla Seoul, ROK.
Transmitted by the IWVTA Informal Group
Summary of software update progress
Japan’s proposal for security regulation
Status of the Informal Working Group on ACSF
Status of the Informal Working Group on ACSF
Outcome TFCS-06 // June TIA, Arlington/VA (USA)
Informal document GRVA nd GRVA, 28 Jan Feb. 2019
Original slide of TFCS-ahSU2-02-Rev1
Exchange and Sharing of Economic Data
Status report from UNECE Task Force on Cyber Security &
Japan’s opinion on SWIN
New Assessment & Test Methods
Lifecycle of vehicle type vs Lifetime of one vehicle
Informal document GRVA st GRVA, September 2018
Replies by the Task Force to the comments provided by GRVA members
Task Force – Cyber Security, Data Protection and Over-the-Air issues
Status report of TF-CS/OTA
Discussion points for Interpretation Document on Cybersecurity
Draft Guidelines for application of the Unique Identifier (UI)
Safety concept for automated driving systems
Why a „test phase“? Overview
Open Letter - Summary of Responses
International Telecommunication Union CITS meeting 8 March 2019 Geneva Status report of the GRVA activities Context, current activities and impact François.
Informal document GRSG Rev.1
Software Update - Type approval related issues -
Overview of the recommendations on software updates
Highlights of the 177th WP.29 session and
Input for ad hoc on software update on 7th Dec. from Japan
Informal document GRSG
Issues identified in connection with the work of TF-CS/OTA
Input for ad hoc on software update on 7th Dec. from Japan
Status report on the activities of TF-CS/OTA
Inputs Regard to “Test Phase” to TFCS
Alignment of Part 4B with ISAE 3000
Report of Japanese Test Phase <Cyber Security>
ACSF-17 – Industry Preparation
A proposal for approach to proceed work in Cybersecurity TF
ACSF B2 and C2 Industry expectations from ACSF IG Tokyo meeting
Summary on initial findings
Japan CS/OTA 15th session, Geneva 27-28, August 2019
Access to data requirementS
EDR/DSSAD IWG Status Report
Presentation transcript:

Status report on the activities of TF-CS/OTA Transmitted by the Secretary of TF-CS/OTA Status report on the activities of TF-CS/OTA 12th session WP.29 IWG ITS/AD 22 June 2017, UNECE, Geneva

Status report on the activities of TF-CS/OTA Cyber security: The group has finished its task to identify key risks and threats, resulting in a table of threats (see TFCS-05-05-Rev2) The table covers all cyber security threats identified. This includes threats associated with cyber security, data protection and software updates (incl. over-the-air issues) The group has started to develop mitigations for the threats, based on an extended CIA approach (CIA = Confidentiality, Integrity, Availability) leading to 18 mitigations The ITS/AD cyber security guideline principles, the UK DfT principles for cyber security and other references have also been considered in the development of mitigations

Status report on the activities of TF-CS/OTA Cyber security (continued): The group agreed to consider “pre attack” (prevention), “during attack” (detection) and “post attack” (response) Reference documents identified for mitigations are : ENISA report „Cyber Security and Resilience of Smart Cars” TFCS-03-09 UK DfT Cyber Security principles TFCS-03-07 NHTSA Cyber Security Guideline TFCS-03-08 IPA “Approaches for Vehicle Information Security” (Japan) TFCS-04-05 UNECE Cyber security guideline (ITS/AD) WP.29/2017/46 SAE J 3061 ISO 19790 ISO 26262 US Auto ISAC (report by Booz Allen Hamilton) https://www.automotiveisac.com/best-practices/ - An ad hoc web meeting will be held, with the aim to conclude work on mitigations (Mid/End July 2017)

Status report on the activities of TF-CS/OTA Software updates: The group is considering both pre- and post-registration updates. It is acknowledged that post-registration updates are dealt with nationally. Therefore any output relating to this will be as guidance to support national processes. To manage configuration control for the approval process the “S/W TAN” approach has been proposed. This may also be used during PTI/CTI. An ad hoc meeting for interested parties dealing with the S/W update approval process incl. S/W TAN was agreed Principle: Cover the type approval relevant software versions of all impacted ECUs by one Type Approval Number for each system type approval.

Status report on the activities of TF-CS/OTA Software updates (continued): - Summary of actions with relation to the timeline of a software update and its impact on type approval (TA) moment of update no impact limited impact severe impact Initial type approval (TA) not applicable Existing TA, before Certificate of Conformity (CoC) no action extension TA new TA Existing TA, after CoC, before registration extension TA and new CoC new TA and new CoC Existing TA, after registration, by OEM extension TA or individual approval or approval with limited scope. Registration according to national rules new TA or individual approval or approval with limited scope. Registration according to national rules Existing TA, after registration, not by OEM (multi stage) new National approval. Registration according to national rules

Status report on the activities of TF-CS/OTA Software updates (continued): Further consideration will be given to: Software Type Approval Number (S/W TAN): Review approach for „Whole Vehicle S/W TAN“ vs. „System-based S/W TAN“ 2) Administrative process to realize S/W TAN concept: Review approach for linking S/W versions, ECU‘s involved, etc. with S/W TAN Clarify roles and responsibilities in the process, e.g. involvement of Technical Service, etc. Role of customer involvement Information requirements to support the process

Status report on the activities of TF-CS/OTA Software updates (continued): 3) Safety aspects of software updates: Develop principles/recommendations for safe execution of software updates Impact of different reasons for updates on the requirements/approval process The group agreed that systems with „deep learning/self learning“ is currently out of scope It was noted that an electronic CoC/DoC may be needed to support the process

Status report on the activities of TF-CS/OTA Data protection Cyber Security Software updates Legal aspects Security aspects Security aspects Type approval aspects Safety aspects pre- registration post- registration Threat analysis out of scope Table of threats Develop recommendation for safe execution Develop flow diagram Define mitigation principles Define approval method Develop guidance/recommendation for ITS/AD

Status report on the activities of TF-CS/OTA TF-CS/OTA is „on track“ to deliver guidance papers/ recommendations on the issues of cyber security and software updates as planned by the end of 2017 Start drafting guidance papers/recommendation Finalize work ad hoc Threats2 April 2017 Webmeeting TFCS-06 13.-14.06.2017 Washington ad hoc S/W TAN 02 August 2017 Hamburg TFCS-08 11-12 Oct. 2017 Tokyo TFCS-10 December 2017 London (?) TFCS-05 10.-11.05.2017 Paris ad hoc Mitigations mid/end July Webmeeting TFCS-07 30-31 Aug. 2017 Netherlands TFCS-09 9 -10 Nov. 2017 Geneva Cyber security threats (table) confirmed Finalize mitigations + S/W update process