Showing posts with label mission-critical. Show all posts
Showing posts with label mission-critical. Show all posts

Thursday, December 15, 2016

Holistic Security for the Software-Defined Car

Bill Boldt
Sr. Business Development Manager, Security
Blackberry Certicom



Due to high profile hacks on cars, it is hard to argue that without security you can have safety.   So, security is emerging as perhaps the most important factor in the evolution of the connected autonomous car.
 
Cars are the most software intensive systems in the universe with far more lines of code than even a state of the art jet fighter. By being such complex digital systems they have become prime targets for attack, and that is where cryptographic countermeasures come in.

Connecting the dots – in the emerging software-defined world safety increasingly
comes from security and security comes from cryptography. Robust cryptographic security implementation is how you increase trust, and when it comes to a car every system must be
trusted: inside the car, in the smart infrastructure, in emerging applications-based ecosystems, and in the manufacturing supply chain. When considering automotive security,
many factors come into play. Some are noted here:

                       
  • Automotive security fundamentally depends on the security of the operating system. For example, a microkernel architecture that separates critical OS components into their own protected memory partitions, provides temporal separation, and provides network security, among other things can greatly reduce the attack surface.
  • Security assets (crypto keys, serial numbers, etc.) must be securely installed into electronic devices such as Electronic Control Units (ECUs), domain/area controllers, and other processors. This process is called "personalization".
  • Electronic devices will often get personalized and installed into vehicles in globally located factories, which should utilize secure equipment and processes to ensure security of the devices.
  •  Devices must be updateable at dealers and repair shops. 
  • Aftermarket suppliers must be able to sell and update secure devices, and
  • OEMs must be able to authorize or not authorize specific electronic devices at
    manufacturing time and after the car is in use (for example to enforce warrantee policies).
And, there are many more.


Personalizing a device such as a networked ECU means that it will become one of a kind. However, by definition that device cannot be used anywhere else. It becomes a unique stock keeping unit (SKU), which is averse to the purpose of flexible, just in time manufacturing flows. Security versus manufacturing flexibility is a serious trade off that will play a part of any automotive security design decision.


Security robustness versus cost is another critical trade off, and applies to the manufacturing infrastructure and the design of the secure systems inside and outside the vehicle. Because security must be injected in the factory and in the field, a secure manufacturing system must have global reach, be manageable on a distributed basis, be updatable by various entities, and remain secure for years. In addition, security updates will increasingly be made over the air, and the systems that do that must by highly secure while being easy to manage. To maintain the maximum amount of flexibility, personalization and updating should be moved as close as possible to the very last minute, which is becoming a critical objective of the global manufacturing blue print. 


Blackberry Brings It All Together




In the car, outside the car, and in the manufacturing supply chain, security must be designed with best practices in mind right from the start, and BlackBerry Professional Services can help with that. BlackBerry QNX provides mission-critical automotive software proven in the automotive market.  QNX software is well known for safety and new products are setting the new standard for security.

BlackBerry's Certicom subsidiary provides certified cryptographic code and design consulting, as well as secure equipment and managed services that harden the automotive supply chain. Completing the picture, BlackBerry's secure OTA managed services make it easy to update software and security assets over the air. When it comes to automotive security, BlackBerry brings it all together.


Wednesday, October 19, 2016

Crossroads - INNOTRANS 2016


Terry Staycer
Global Business Development Manager 
BlackBerry






Readers of this blog might be interested in hearing how demands for software safety and security are growing not only in automotive, but in other transportation areas as well – specifically, the railway industry.
 

Last month in Berlin, the 11th annual largest global railway industry event took place.  It was a smashing four-day success in terms of attendance and powerful discussions.   I was honored to attend this event. Overall, the hot topics revolved around improving mobility issues, digitization in rail passenger and freight transport, and technology for digital services.  Safety and security  remain key points of concern.   

QNX's hardware partner, MEN Micro, introduced Internet on trains to ease passenger communication and increase convenience.  However, that comes with increasing risk in terms of bad actors' being able to hack into a rail network.  It is critical to ensure that rail systems are at their most secure and that there is no potential violation to a train.
 
Here is a summary of some other key takeaways from what is the leading trade fair for transport technology:

Evident Re-Focusing
There is a re-focusing of development regarding interlocking and signal control among many of the big rail players such as Alstom, Bombardier, GE, and many others.  Application code, hardware, electronics, and sensors are being outsourced. The rail industry is maturing like the automotive market.

SIL 2. All the way
Customers are pursuing requirements from European and Chinese regulatory commissions, and increasingly those requirements are emerging as SIL-2, and not the anticipated SIL-4.  With these lower Safety Integrity Levels (SILs), the level of system failure increases. Of course customers are still asking for SIL-4, but this is an interesting trend to note.

Security is Critical
Security is a maturing requirement.  At the recent Deutsche Bahn Cyber Security Congress security was a top priority, and it was a hot topic at Innotrans as well. Some of the questions emerging about the security include: If there is a cybersecurity violation, how long does it take to recover? And, how does one architect a system for resiliency to cyberattacks?

Fail Safe vs. availability

Fail safe is good, but high availability is a demand. This topic dovetails into the statement above. Systems must be available in a sense that requires redundancy and fail safe. QNX is well positioned to address this trend with a microkernel based operating system architecture that delivers high-availability and reliability, making it perfect for mission-critical operations such as rail safety. 

China and North America Expansion
China was the most represented company outside of Germany.  The Chinese high speed rail network will span 25,631 KM by 2030. China will boast a total track length of 120,000 KM by 2020.  In addition, North America will invest over $9.8 Billion per year  towards modernization continuing until 2022. Signaling, locomotives, and rail cars have the highest priority.

It is exciting to watch these trends develop and see which new ones will emerge.   

Already looking forward to Innotrans 2017!