SlideShare une entreprise Scribd logo
1  sur  24
Télécharger pour lire hors ligne
2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
2018-03-13
Alexander Much, Rudolf Grave
Safety and Security Aspects of
Automotive High Performance
Controllers
22018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Changes in E/E architecture
Safety
Security
Outlook
Agenda
Safety and Security Aspects of Automotive High Performance Controllers
2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Changes in E/E architecture
42018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
We need to completely re-think the E/E architecture:
• Domain or zonal architectures
• Centralized computing units
• High-speed, reliable and dependable networking
• Connected vehicle within infrastructure eco-systems
What comes first?
Mobile on Wheels or Wheels on Mobile?
Safety and Security Aspects of Automotive High Performance Controllers
Source: https://pxhere.com/en/photo/1064249, CC0 Public Domain
Cloud and mobile first!
52018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Most prominent answer:
„Of course, my car!“
People don‘t realize:
• How many security solutions are in today‘s phones
• Cloud and phones set the „state-of-the-art“
• ... not cars!
What needs to be „more“ secure?
Phone and Cloud vs. Vehicle
Safety and Security Aspects of Automotive High Performance Controllers
Source: https://pixabay.com/en/smartphone-phone-castle-key-1868489/, CC0 Creative Commons
62018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Evolution of E/E Architectures
Safety and Security Aspects of Automotive High Performance Controllers
today tomorrow future
Domain Architecture Centralized Architecture Zoned Architecture
• Signal based communication
• System of ECUs
• Predictable communication
• Function orientated topology
• Central computing nodes
• Mix of signal based and service
orientated communication
• Partly centralized functions
• Software upgradability
• IP/Ethernet communication
• Centralized applications/functions
• Computing power for AD and AI
• Anything anywhere (sensors/actors)
• Architecture follows software/ system
demands
72018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
• Centralized computing platform (yellow)
• Zonal ECUs in a ring architecture (green)
• Actors and sensors (purple) connected via Zonal ECUs
• Applications are running on centralized computing
platforms, zonal ECUs sensors and actors provide
standardized service interfaces.
• Reduction in wiring / weight and cost
Zonal E/E Architecture
Safety and Security Aspects of Automotive High Performance Controllers
Zonal E/E Architecture
For comparison: Star Wiring
82018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Connected E/E Architecture (Logical View)
Safety and Security Aspects of Automotive High Performance Controllers
UI
Computing
Cluster
Computing
Cluster(s)
Smart Antenna
Gateway IO Concentrators,
Actors, Sensors
Smart
Sensors
Smart
Sensors
Steering
Braking Battery
Engine
Back-end
System
Gigabit
Ethernet
Reliable ECU
Performance ECU
IO Concentrators
Back-end Server
92018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Use-case: remote update
Safety and Security Aspects of Automotive High Performance Controllers
Architectural principles:
• Central external
connection
• Distribution of updates
across multiple ECUs
Supporting features
• Coordinated A/B Update
across ECUs
• Secure networks and
communication
• Layered security
architecture
Smart Antenna
Gateway
Back-end
System
Reliable ECU
Performance ECU
IO Concentrators
Back-end Server
102018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Use-case: ADAS
Safety and Security Aspects of Automotive High Performance Controllers
Architectural principles :
• Separation between
planning and
performance parts
• Hierarchical safety
architecture
Supporting features
• ASIL-B performance
platform
• ASIL-D classic platform
• Hierarchical, distributed
runtime supervision
Smart Antenna
Gateway
Back-end
System
Reliable ECU
Performance ECU
IO Concentrators
Back-end Server
112018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Principals of a future architecture
Safety and Security Aspects of Automotive High Performance Controllers
HPC = High performance controller
HPC-1 HPC-2 HPC-3
Horizontal deployment of functions
RT-SW RT-SW RT-SW RT-SW
“logic”-SW “logic”-SW “logic”-SW “logic”-SW “logic”-SW “logic”-SW
Computing
layer
Real time
and sensor/
actuator layer
Back-end
Vehicle API / Basic services / information layer
Every information anywhere” –
enables horizontal deployment
of services and updating
service.
 But need to be controlled
for safety and security reasons
2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Safety
132018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Example: Fail-Operational Networking
Safety and Security Aspects of Automotive High Performance Controllers
Fault-tolerant communication
Redundant
communication
paths
Redundant paths
between Eth
switches (RedM or
IEEE 802.1CB)
Duplicate network
for CAN/FlexRay
(nodes connected
via 2 links)
Fault-tolerant application services Fault-tolerant
network services
Communication
path quality
Com SW quality:
focus on safety
related feature and
FFI to all other
parts
Com controller and
switch quality
Parallel active
service
Service instance A’
active
Service instance
A’’ active
B selects data
from A’ or A’’
based on priority
Primary/Backup
service
Primary instance
A’ active
Backup instance
A’’ in stand-by,
becomes active
when primary fails
(no heartbeat)
Critical service
with redundancy
(e.g. backup time
master)
Locked service –
no changes on
committed, critical
resources (e.g. ECU
shutdown lock,
network
bandwidth lock)
142018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Separation of concerns:
• Performance
• Safety
• Security
Mixture of Classic and Adaptive:
• Safety closely related to real-
time domain
• Plenty of room for legacy
applications
High Performance Controllers: SW Architecture
Safety and Security Aspects of Automotive High Performance Controllers
AUTOSAR OS
Adaptive AUTOSAR
QM
App App
MCU
Classic AUTOSAR
Automotive-grade Hypervisor
Adaptive AUTOSAR
Safety
App
LINUX OS LINUX OS
Classic AUTOSAR
Safety
App
Safety Cores
Safety OS
Performance Cores
Performance Partitions for Vehicle & Consumer Functions Safety Partition
Security
TEE
App
Security HW
Trusted OS
Security Partition
152018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Classic AUTOSAR
Components
Example: Distributed Health Management
Safety and Security Aspects of Automotive High Performance Controllers
Classic AUTOSAR
Components
Lockstep
Safety OS
WDG
Core CoreCore Core
Safety
Core
Safety
Core
Core…. CoreCore
Health
Control
Bootloader
Hypervisor
Privileged Partition
Adaptive AUTOSAR on
Linux
Health Manager
Vehicle Functions Partition
Adaptive AUTOSAR on Linux
Container
Vehicle
Function
Virtual
Resources
Container
Vehicle
Function
Virtual
Resources
Container
Vehicle
Function
Virtual
Resources
Pesistency
Manager
Execution
manager
Health
Manager
Diagnostic
Manager
Virtual
Resources
Physical Resources
….
Classic AUTOSAR
Safety
Core
Safety
Core
Lockstep
Safety OS
WDG
Health
Control
Classic AUTOSAR
Monitor Control
2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Security
172018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Security >>> Safety
• Connectivity, Ethernet and High-Performance ECUs open the
car to new threats
• More data  more lucrative to attack
• Product development life-cycles (PLCs) don‘t suffice, a switch to
service life-cycles (SLCs) needed:
– Automotive quality assurance in DevOps environments?
– Regulatory clearance?
– Field monitoring and incident response management
– Third-party security observation, also for open source software
• Cars will need to be updated frequently
Which has more „impact“?
Safety and Security
Safety and Security Aspects of Automotive High Performance Controllers
Source: http://maxpixel.freegreatpicture.com/Virus-Computer-Word-Security-Trojan-Cloud-Cyber-2120014, CC0 Public Domain
182018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Secure System Layers
Safety and Security Aspects of Automotive High Performance Controllers
Secure Environment
Secure External
Communication
Secure Network
Segmentation
Secure OnBoard
Communication
Secure Platform
Secure Boot
Secure Hardware Element
Secure Update / Diagnostics
- Applications
- Flashware
Separation / Isolation
- Memory Protection
- Scheduling Policies
- Access Control
AUTOSAR SecOC
Ethernet Security
Domain Separation
Trust Zones
IDS/ADS
Firewall
Secure External Channels
- TLS
Secure Logging Agent
Secure Backend Infrastructure
192018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Limit the number of ECUs with off-board
connections
Restrict access to the network (I)
Safety and Security Aspects of Automotive High Performance Controllers
Today: multiple connections
202018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
• Divide network into security zones, e.g. extern, “demilitarized”, internal.
• Restrict traffic between zones: Physical split or separation via VLANs:
Not only extern-intern, but also intern-intern, e.g. infotainment to powertrain
Restrict access to the network (II)
Safety and Security Aspects of Automotive High Performance Controllers
VLAN Tagging to separate external – internal
• External frames are tagged with an orange VLAN tag at the switch
• Only nodes assigned to the orange VLAN can receive frames from the
external tester
• Frames to be sent to external tester, are sent via the orange VLAN – the
switch at the gateway removes the orange VLAN tags before forwarding it
to the tester
VLAN Tagging to separate internal networks
• ECUs from Infotainment (blue VLAN), chassis (green VLAN) and
powertrain (yellow VLAN) can be separated
• Traffic between VLANs require a switch or Gateway
Tester
212018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Example: Platform Security Layers
Safety and Security Aspects of Automotive High Performance Controllers
Operating Systems
Containers
Hardware
Classic
µC
HSM Performance µP SwitchSecure EnginePerformance Cores
Hypervisor
Processes
Resource Access Control
Intermediate Address Space
Separation (1st-Stage MMU)
Control Flow Integrity
Hardware Resource Separation
Physical Address Space Separation
2nd-Stage MMU
Scheduling Domains
Resource Constraints
Control Flow Integrity
Virtual Address Space
Crypto Accelerators
3 Core Logic (Secure, Public & PKA)
Dedicated RAM/ROM (key material)
eFuses
Life Cycle Management
Hardware Access Protection
Crypto AcceleratorsHSM (EVITA medium)
HIS SHE support
DoS prevention
VLAN Tagging
Static ARP tables
Monitoring Ports
2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Outlook
232018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
Outlook: Interesting Times...
Safety and Security Aspects of Automotive High Performance Controllers
machine learning crowed sourced data system of systems third party access
personalization shortened
development cycles
evolution after SOP new topics
new business models
?
2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018.
All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights.
www.elektrobit.com
alexander.much@elektrobit.com
Get in touch!

Contenu connexe

Tendances

Multicore and AUTOSAR
Multicore and AUTOSARMulticore and AUTOSAR
Multicore and AUTOSARHansang Lee
 
Adaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaCore
 
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected VehiclesWebinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected VehiclesHARMAN Connected Services
 
Connected Car Security
Connected Car SecurityConnected Car Security
Connected Car SecuritySuresh Mandava
 
Over-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected carOver-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected carPratik Desai, PhD
 
Overview of automotive network protocol
Overview of automotive network protocolOverview of automotive network protocol
Overview of automotive network protocolpoojashinde212
 
From Cybersecurity to Cyber Resilience
From Cybersecurity to Cyber ResilienceFrom Cybersecurity to Cyber Resilience
From Cybersecurity to Cyber Resilienceaccenture
 
Data Driven Development of Autonomous Driving at BMW
Data Driven Development of Autonomous Driving at BMWData Driven Development of Autonomous Driving at BMW
Data Driven Development of Autonomous Driving at BMWDataWorks Summit
 
Cybersecurity in Oil Gas Industry
Cybersecurity in Oil Gas IndustryCybersecurity in Oil Gas Industry
Cybersecurity in Oil Gas IndustryTunde Ogunkoya
 
Ids sdd-jlr manual 02 02-12 (1)
Ids sdd-jlr manual 02 02-12 (1)Ids sdd-jlr manual 02 02-12 (1)
Ids sdd-jlr manual 02 02-12 (1)Boualam Mohammed
 
Understanding UNECE WP.29 regulations on cybersecurity
Understanding UNECE WP.29 regulations on cybersecurityUnderstanding UNECE WP.29 regulations on cybersecurity
Understanding UNECE WP.29 regulations on cybersecurityDominik Strube
 
Introduction to Embedded Systems
Introduction to Embedded SystemsIntroduction to Embedded Systems
Introduction to Embedded SystemsMohamed Tarek
 
Webinar presentation on AUTOSAR Multicore Systems
Webinar presentation on AUTOSAR Multicore SystemsWebinar presentation on AUTOSAR Multicore Systems
Webinar presentation on AUTOSAR Multicore SystemsKPIT
 
Connected & Autonomous vehicles: cybersecurity on a grand scale v1
Connected & Autonomous vehicles: cybersecurity on a grand scale v1Connected & Autonomous vehicles: cybersecurity on a grand scale v1
Connected & Autonomous vehicles: cybersecurity on a grand scale v1Bill Harpley
 
MITRE ATT&CK Updates: ICS
MITRE ATT&CK Updates: ICSMITRE ATT&CK Updates: ICS
MITRE ATT&CK Updates: ICSMITRE ATT&CK
 

Tendances (20)

Multicore and AUTOSAR
Multicore and AUTOSARMulticore and AUTOSAR
Multicore and AUTOSAR
 
CVSS
CVSSCVSS
CVSS
 
Adaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR ArchitectureAdaptive AUTOSAR - The New AUTOSAR Architecture
Adaptive AUTOSAR - The New AUTOSAR Architecture
 
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected VehiclesWebinar - Automotive SOC - Security Data Analytics for Connected Vehicles
Webinar - Automotive SOC - Security Data Analytics for Connected Vehicles
 
Connected Car Security
Connected Car SecurityConnected Car Security
Connected Car Security
 
Secure Embedded Systems
Secure Embedded SystemsSecure Embedded Systems
Secure Embedded Systems
 
Over-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected carOver-the-air (OTA) updates and the Connected car
Over-the-air (OTA) updates and the Connected car
 
Cissp Training PPT
Cissp Training PPTCissp Training PPT
Cissp Training PPT
 
Autosar MCAL (Microcontroller Abstraction Layer)
Autosar MCAL (Microcontroller Abstraction Layer)Autosar MCAL (Microcontroller Abstraction Layer)
Autosar MCAL (Microcontroller Abstraction Layer)
 
Overview of automotive network protocol
Overview of automotive network protocolOverview of automotive network protocol
Overview of automotive network protocol
 
From Cybersecurity to Cyber Resilience
From Cybersecurity to Cyber ResilienceFrom Cybersecurity to Cyber Resilience
From Cybersecurity to Cyber Resilience
 
Data Driven Development of Autonomous Driving at BMW
Data Driven Development of Autonomous Driving at BMWData Driven Development of Autonomous Driving at BMW
Data Driven Development of Autonomous Driving at BMW
 
Cybersecurity in Oil Gas Industry
Cybersecurity in Oil Gas IndustryCybersecurity in Oil Gas Industry
Cybersecurity in Oil Gas Industry
 
Ids sdd-jlr manual 02 02-12 (1)
Ids sdd-jlr manual 02 02-12 (1)Ids sdd-jlr manual 02 02-12 (1)
Ids sdd-jlr manual 02 02-12 (1)
 
Automotive Hacking
Automotive Hacking Automotive Hacking
Automotive Hacking
 
Understanding UNECE WP.29 regulations on cybersecurity
Understanding UNECE WP.29 regulations on cybersecurityUnderstanding UNECE WP.29 regulations on cybersecurity
Understanding UNECE WP.29 regulations on cybersecurity
 
Introduction to Embedded Systems
Introduction to Embedded SystemsIntroduction to Embedded Systems
Introduction to Embedded Systems
 
Webinar presentation on AUTOSAR Multicore Systems
Webinar presentation on AUTOSAR Multicore SystemsWebinar presentation on AUTOSAR Multicore Systems
Webinar presentation on AUTOSAR Multicore Systems
 
Connected & Autonomous vehicles: cybersecurity on a grand scale v1
Connected & Autonomous vehicles: cybersecurity on a grand scale v1Connected & Autonomous vehicles: cybersecurity on a grand scale v1
Connected & Autonomous vehicles: cybersecurity on a grand scale v1
 
MITRE ATT&CK Updates: ICS
MITRE ATT&CK Updates: ICSMITRE ATT&CK Updates: ICS
MITRE ATT&CK Updates: ICS
 

Similaire à Safety and Security Aspects of Automotive High Performance Controllers

20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"
20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"
20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"Alexander Much
 
MIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication Networks
MIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication NetworksMIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication Networks
MIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication NetworksMIPI Alliance
 
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"Alexander Much
 
Solutions for ADAS and AI data engineering using OpenPOWER/POWER systems
Solutions for ADAS and AI data engineering using OpenPOWER/POWER systemsSolutions for ADAS and AI data engineering using OpenPOWER/POWER systems
Solutions for ADAS and AI data engineering using OpenPOWER/POWER systemsGanesan Narayanasamy
 
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture DesignTowards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture DesignRealTime-at-Work (RTaW)
 
Is Linux ready for safety related applications?
Is Linux ready for safety related applications?Is Linux ready for safety related applications?
Is Linux ready for safety related applications?Alexander Much
 
Elisa Polystar Automate Presentation Mobitel 240822.pdf
Elisa Polystar Automate Presentation Mobitel 240822.pdfElisa Polystar Automate Presentation Mobitel 240822.pdf
Elisa Polystar Automate Presentation Mobitel 240822.pdfNuwanChandimal1
 
In Automotive Environments - HU Michel
In Automotive Environments - HU MichelIn Automotive Environments - HU Michel
In Automotive Environments - HU Michelmfrancis
 
Intelligent, safe and reliable power distribution for electric vehicles
Intelligent, safe and reliable power distribution for electric vehiclesIntelligent, safe and reliable power distribution for electric vehicles
Intelligent, safe and reliable power distribution for electric vehiclesEaton Corporation
 
How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...
How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...
How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...ThousandEyes
 
IoT Meetup September 2019
IoT Meetup September 2019IoT Meetup September 2019
IoT Meetup September 2019IoT Academy
 
Open Source for Industry 4.0 – Open IoT Summit NA 2018
Open Source for Industry 4.0 – Open IoT Summit NA 2018Open Source for Industry 4.0 – Open IoT Summit NA 2018
Open Source for Industry 4.0 – Open IoT Summit NA 2018Benjamin Cabé
 
VMware Solutions for the Connected Car
VMware Solutions for the Connected CarVMware Solutions for the Connected Car
VMware Solutions for the Connected CarAngel Villar Garea
 
Effective IIoT Implementation combining different data sources
Effective IIoT Implementation combining different data sourcesEffective IIoT Implementation combining different data sources
Effective IIoT Implementation combining different data sourcesM2M Alliance e.V.
 
Presentation cloud services
Presentation   cloud servicesPresentation   cloud services
Presentation cloud servicesxKinAnx
 
IRJET- Review Paper on Iot Based Technology in Automobiles
IRJET-  	  Review Paper on Iot Based Technology in AutomobilesIRJET-  	  Review Paper on Iot Based Technology in Automobiles
IRJET- Review Paper on Iot Based Technology in AutomobilesIRJET Journal
 
Internet of things case studies of edge computing
Internet of things case studies of edge computingInternet of things case studies of edge computing
Internet of things case studies of edge computingKhoonSeang (Richard) Kang
 
Internet of things case studies of edge computing
Internet of things   case studies of edge computingInternet of things   case studies of edge computing
Internet of things case studies of edge computingKhoonSeang (Richard) Kang
 

Similaire à Safety and Security Aspects of Automotive High Performance Controllers (20)

20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"
20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"
20160914 EuroSPI: "Automotive Security: Challenges, Standards and Solutions"
 
MIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication Networks
MIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication NetworksMIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication Networks
MIPI DevCon 2020 | Keynote: Trends in Future In-Vehicle Communication Networks
 
TTTech Company Overview
TTTech Company OverviewTTTech Company Overview
TTTech Company Overview
 
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
20160706 Automotive SYS: "Evolving Needs for Software Systems - Demonstrated"
 
Solutions for ADAS and AI data engineering using OpenPOWER/POWER systems
Solutions for ADAS and AI data engineering using OpenPOWER/POWER systemsSolutions for ADAS and AI data engineering using OpenPOWER/POWER systems
Solutions for ADAS and AI data engineering using OpenPOWER/POWER systems
 
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture DesignTowards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
Towards Computer-Aided, Iterative TSN-and Ethernet-based E/E Architecture Design
 
IBM Cloud to the Edge
IBM Cloud to the EdgeIBM Cloud to the Edge
IBM Cloud to the Edge
 
Is Linux ready for safety related applications?
Is Linux ready for safety related applications?Is Linux ready for safety related applications?
Is Linux ready for safety related applications?
 
Elisa Polystar Automate Presentation Mobitel 240822.pdf
Elisa Polystar Automate Presentation Mobitel 240822.pdfElisa Polystar Automate Presentation Mobitel 240822.pdf
Elisa Polystar Automate Presentation Mobitel 240822.pdf
 
In Automotive Environments - HU Michel
In Automotive Environments - HU MichelIn Automotive Environments - HU Michel
In Automotive Environments - HU Michel
 
Intelligent, safe and reliable power distribution for electric vehicles
Intelligent, safe and reliable power distribution for electric vehiclesIntelligent, safe and reliable power distribution for electric vehicles
Intelligent, safe and reliable power distribution for electric vehicles
 
How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...
How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...
How Schneider Electric Assures Its Salesforce Lightning Migration with Thousa...
 
IoT Meetup September 2019
IoT Meetup September 2019IoT Meetup September 2019
IoT Meetup September 2019
 
Open Source for Industry 4.0 – Open IoT Summit NA 2018
Open Source for Industry 4.0 – Open IoT Summit NA 2018Open Source for Industry 4.0 – Open IoT Summit NA 2018
Open Source for Industry 4.0 – Open IoT Summit NA 2018
 
VMware Solutions for the Connected Car
VMware Solutions for the Connected CarVMware Solutions for the Connected Car
VMware Solutions for the Connected Car
 
Effective IIoT Implementation combining different data sources
Effective IIoT Implementation combining different data sourcesEffective IIoT Implementation combining different data sources
Effective IIoT Implementation combining different data sources
 
Presentation cloud services
Presentation   cloud servicesPresentation   cloud services
Presentation cloud services
 
IRJET- Review Paper on Iot Based Technology in Automobiles
IRJET-  	  Review Paper on Iot Based Technology in AutomobilesIRJET-  	  Review Paper on Iot Based Technology in Automobiles
IRJET- Review Paper on Iot Based Technology in Automobiles
 
Internet of things case studies of edge computing
Internet of things case studies of edge computingInternet of things case studies of edge computing
Internet of things case studies of edge computing
 
Internet of things case studies of edge computing
Internet of things   case studies of edge computingInternet of things   case studies of edge computing
Internet of things case studies of edge computing
 

Dernier

-The-Present-Simple-Tense.pdf english hh
-The-Present-Simple-Tense.pdf english hh-The-Present-Simple-Tense.pdf english hh
-The-Present-Simple-Tense.pdf english hhmhamadhawlery16
 
Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!
Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!
Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!Mint Automotive
 
Mastering Mercedes Engine Care Top Tips for Rowlett, TX Residents
Mastering Mercedes Engine Care Top Tips for Rowlett, TX ResidentsMastering Mercedes Engine Care Top Tips for Rowlett, TX Residents
Mastering Mercedes Engine Care Top Tips for Rowlett, TX ResidentsRowlett Motorwerks
 
原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量
原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量
原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量sehgh15heh
 
EPA Funding Opportunities for Equitable Electric Transportation by Mike Moltzen
EPA Funding Opportunities for Equitable Electric Transportationby Mike MoltzenEPA Funding Opportunities for Equitable Electric Transportationby Mike Moltzen
EPA Funding Opportunities for Equitable Electric Transportation by Mike MoltzenForth
 
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full NightCall Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Nightssuser7cb4ff
 
(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一
(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一
(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一gfghbihg
 
907MTAMount Coventry University Bachelor's Diploma in Engineering
907MTAMount Coventry University Bachelor's Diploma in Engineering907MTAMount Coventry University Bachelor's Diploma in Engineering
907MTAMount Coventry University Bachelor's Diploma in EngineeringFi sss
 
Trent engineer.pptx presentation reports
Trent engineer.pptx presentation reportsTrent engineer.pptx presentation reports
Trent engineer.pptx presentation reportsbasant11731
 
Equity & Freight Electrification by Jose Miguel Acosta Cordova
Equity & Freight Electrification by Jose Miguel Acosta CordovaEquity & Freight Electrification by Jose Miguel Acosta Cordova
Equity & Freight Electrification by Jose Miguel Acosta CordovaForth
 
办理阳光海岸大学毕业证成绩单原版一比一
办理阳光海岸大学毕业证成绩单原版一比一办理阳光海岸大学毕业证成绩单原版一比一
办理阳光海岸大学毕业证成绩单原版一比一F La
 
248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf
248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf
248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdfkushkruthik555
 
Building a Budget by Cat Plein and Josh Rodriguez
Building a Budget by Cat Plein and Josh RodriguezBuilding a Budget by Cat Plein and Josh Rodriguez
Building a Budget by Cat Plein and Josh RodriguezForth
 
原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量
原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量
原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量208367051
 
原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档208367051
 
办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书
办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书
办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书zdzoqco
 
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证jjrehjwj11gg
 
(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一
(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一
(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一ejgeojhg
 
(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样
(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样
(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样whjjkkk
 
Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...
Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...
Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...Forth
 

Dernier (20)

-The-Present-Simple-Tense.pdf english hh
-The-Present-Simple-Tense.pdf english hh-The-Present-Simple-Tense.pdf english hh
-The-Present-Simple-Tense.pdf english hh
 
Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!
Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!
Can't Roll Up Your Audi A4 Power Window Let's Uncover the Issue!
 
Mastering Mercedes Engine Care Top Tips for Rowlett, TX Residents
Mastering Mercedes Engine Care Top Tips for Rowlett, TX ResidentsMastering Mercedes Engine Care Top Tips for Rowlett, TX Residents
Mastering Mercedes Engine Care Top Tips for Rowlett, TX Residents
 
原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量
原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量
原版定制copy澳洲查尔斯顿大学毕业证UC毕业证成绩单留信学历认证保障质量
 
EPA Funding Opportunities for Equitable Electric Transportation by Mike Moltzen
EPA Funding Opportunities for Equitable Electric Transportationby Mike MoltzenEPA Funding Opportunities for Equitable Electric Transportationby Mike Moltzen
EPA Funding Opportunities for Equitable Electric Transportation by Mike Moltzen
 
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full NightCall Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
Call Girls Vastrapur 7397865700 Ridhima Hire Me Full Night
 
(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一
(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一
(USQ毕业证)南昆士兰大学毕业证学位证成绩单修改留信学历认证原版一比一
 
907MTAMount Coventry University Bachelor's Diploma in Engineering
907MTAMount Coventry University Bachelor's Diploma in Engineering907MTAMount Coventry University Bachelor's Diploma in Engineering
907MTAMount Coventry University Bachelor's Diploma in Engineering
 
Trent engineer.pptx presentation reports
Trent engineer.pptx presentation reportsTrent engineer.pptx presentation reports
Trent engineer.pptx presentation reports
 
Equity & Freight Electrification by Jose Miguel Acosta Cordova
Equity & Freight Electrification by Jose Miguel Acosta CordovaEquity & Freight Electrification by Jose Miguel Acosta Cordova
Equity & Freight Electrification by Jose Miguel Acosta Cordova
 
办理阳光海岸大学毕业证成绩单原版一比一
办理阳光海岸大学毕业证成绩单原版一比一办理阳光海岸大学毕业证成绩单原版一比一
办理阳光海岸大学毕业证成绩单原版一比一
 
248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf
248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf
248649330-Animatronics-Technical-Seminar-Report-by-Aswin-Sarang.pdf
 
Building a Budget by Cat Plein and Josh Rodriguez
Building a Budget by Cat Plein and Josh RodriguezBuilding a Budget by Cat Plein and Josh Rodriguez
Building a Budget by Cat Plein and Josh Rodriguez
 
原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量
原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量
原版1:1定制(IC大学毕业证)帝国理工学院大学毕业证国外文凭复刻成绩单#电子版制作#留信入库#多年经营绝对保证质量
 
原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档
原版1:1定制阳光海岸大学毕业证(JCU毕业证)#文凭成绩单#真实留信学历认证永久存档
 
办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书
办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书
办理萨省大学毕业证成绩单|购买加拿大USASK文凭证书
 
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
原版工艺美国普林斯顿大学毕业证Princeton毕业证成绩单修改留信学历认证
 
(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一
(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一
(Griffith毕业证)格里菲斯大学毕业证毕业证成绩单修改留信学历认证原版一比一
 
(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样
(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样
(办理学位证)墨尔本大学毕业证(Unimelb毕业证书)成绩单留信学历认证原版一模一样
 
Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...
Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...
Transportation Electrification Funding Strategy by Jeff Allen and Brandt Hert...
 

Safety and Security Aspects of Automotive High Performance Controllers

  • 1. 2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. 2018-03-13 Alexander Much, Rudolf Grave Safety and Security Aspects of Automotive High Performance Controllers
  • 2. 22018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Changes in E/E architecture Safety Security Outlook Agenda Safety and Security Aspects of Automotive High Performance Controllers
  • 3. 2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Changes in E/E architecture
  • 4. 42018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. We need to completely re-think the E/E architecture: • Domain or zonal architectures • Centralized computing units • High-speed, reliable and dependable networking • Connected vehicle within infrastructure eco-systems What comes first? Mobile on Wheels or Wheels on Mobile? Safety and Security Aspects of Automotive High Performance Controllers Source: https://pxhere.com/en/photo/1064249, CC0 Public Domain Cloud and mobile first!
  • 5. 52018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Most prominent answer: „Of course, my car!“ People don‘t realize: • How many security solutions are in today‘s phones • Cloud and phones set the „state-of-the-art“ • ... not cars! What needs to be „more“ secure? Phone and Cloud vs. Vehicle Safety and Security Aspects of Automotive High Performance Controllers Source: https://pixabay.com/en/smartphone-phone-castle-key-1868489/, CC0 Creative Commons
  • 6. 62018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Evolution of E/E Architectures Safety and Security Aspects of Automotive High Performance Controllers today tomorrow future Domain Architecture Centralized Architecture Zoned Architecture • Signal based communication • System of ECUs • Predictable communication • Function orientated topology • Central computing nodes • Mix of signal based and service orientated communication • Partly centralized functions • Software upgradability • IP/Ethernet communication • Centralized applications/functions • Computing power for AD and AI • Anything anywhere (sensors/actors) • Architecture follows software/ system demands
  • 7. 72018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. • Centralized computing platform (yellow) • Zonal ECUs in a ring architecture (green) • Actors and sensors (purple) connected via Zonal ECUs • Applications are running on centralized computing platforms, zonal ECUs sensors and actors provide standardized service interfaces. • Reduction in wiring / weight and cost Zonal E/E Architecture Safety and Security Aspects of Automotive High Performance Controllers Zonal E/E Architecture For comparison: Star Wiring
  • 8. 82018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Connected E/E Architecture (Logical View) Safety and Security Aspects of Automotive High Performance Controllers UI Computing Cluster Computing Cluster(s) Smart Antenna Gateway IO Concentrators, Actors, Sensors Smart Sensors Smart Sensors Steering Braking Battery Engine Back-end System Gigabit Ethernet Reliable ECU Performance ECU IO Concentrators Back-end Server
  • 9. 92018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Use-case: remote update Safety and Security Aspects of Automotive High Performance Controllers Architectural principles: • Central external connection • Distribution of updates across multiple ECUs Supporting features • Coordinated A/B Update across ECUs • Secure networks and communication • Layered security architecture Smart Antenna Gateway Back-end System Reliable ECU Performance ECU IO Concentrators Back-end Server
  • 10. 102018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Use-case: ADAS Safety and Security Aspects of Automotive High Performance Controllers Architectural principles : • Separation between planning and performance parts • Hierarchical safety architecture Supporting features • ASIL-B performance platform • ASIL-D classic platform • Hierarchical, distributed runtime supervision Smart Antenna Gateway Back-end System Reliable ECU Performance ECU IO Concentrators Back-end Server
  • 11. 112018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Principals of a future architecture Safety and Security Aspects of Automotive High Performance Controllers HPC = High performance controller HPC-1 HPC-2 HPC-3 Horizontal deployment of functions RT-SW RT-SW RT-SW RT-SW “logic”-SW “logic”-SW “logic”-SW “logic”-SW “logic”-SW “logic”-SW Computing layer Real time and sensor/ actuator layer Back-end Vehicle API / Basic services / information layer Every information anywhere” – enables horizontal deployment of services and updating service.  But need to be controlled for safety and security reasons
  • 12. 2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Safety
  • 13. 132018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Example: Fail-Operational Networking Safety and Security Aspects of Automotive High Performance Controllers Fault-tolerant communication Redundant communication paths Redundant paths between Eth switches (RedM or IEEE 802.1CB) Duplicate network for CAN/FlexRay (nodes connected via 2 links) Fault-tolerant application services Fault-tolerant network services Communication path quality Com SW quality: focus on safety related feature and FFI to all other parts Com controller and switch quality Parallel active service Service instance A’ active Service instance A’’ active B selects data from A’ or A’’ based on priority Primary/Backup service Primary instance A’ active Backup instance A’’ in stand-by, becomes active when primary fails (no heartbeat) Critical service with redundancy (e.g. backup time master) Locked service – no changes on committed, critical resources (e.g. ECU shutdown lock, network bandwidth lock)
  • 14. 142018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Separation of concerns: • Performance • Safety • Security Mixture of Classic and Adaptive: • Safety closely related to real- time domain • Plenty of room for legacy applications High Performance Controllers: SW Architecture Safety and Security Aspects of Automotive High Performance Controllers AUTOSAR OS Adaptive AUTOSAR QM App App MCU Classic AUTOSAR Automotive-grade Hypervisor Adaptive AUTOSAR Safety App LINUX OS LINUX OS Classic AUTOSAR Safety App Safety Cores Safety OS Performance Cores Performance Partitions for Vehicle & Consumer Functions Safety Partition Security TEE App Security HW Trusted OS Security Partition
  • 15. 152018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Classic AUTOSAR Components Example: Distributed Health Management Safety and Security Aspects of Automotive High Performance Controllers Classic AUTOSAR Components Lockstep Safety OS WDG Core CoreCore Core Safety Core Safety Core Core…. CoreCore Health Control Bootloader Hypervisor Privileged Partition Adaptive AUTOSAR on Linux Health Manager Vehicle Functions Partition Adaptive AUTOSAR on Linux Container Vehicle Function Virtual Resources Container Vehicle Function Virtual Resources Container Vehicle Function Virtual Resources Pesistency Manager Execution manager Health Manager Diagnostic Manager Virtual Resources Physical Resources …. Classic AUTOSAR Safety Core Safety Core Lockstep Safety OS WDG Health Control Classic AUTOSAR Monitor Control
  • 16. 2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Security
  • 17. 172018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Security >>> Safety • Connectivity, Ethernet and High-Performance ECUs open the car to new threats • More data  more lucrative to attack • Product development life-cycles (PLCs) don‘t suffice, a switch to service life-cycles (SLCs) needed: – Automotive quality assurance in DevOps environments? – Regulatory clearance? – Field monitoring and incident response management – Third-party security observation, also for open source software • Cars will need to be updated frequently Which has more „impact“? Safety and Security Safety and Security Aspects of Automotive High Performance Controllers Source: http://maxpixel.freegreatpicture.com/Virus-Computer-Word-Security-Trojan-Cloud-Cyber-2120014, CC0 Public Domain
  • 18. 182018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Secure System Layers Safety and Security Aspects of Automotive High Performance Controllers Secure Environment Secure External Communication Secure Network Segmentation Secure OnBoard Communication Secure Platform Secure Boot Secure Hardware Element Secure Update / Diagnostics - Applications - Flashware Separation / Isolation - Memory Protection - Scheduling Policies - Access Control AUTOSAR SecOC Ethernet Security Domain Separation Trust Zones IDS/ADS Firewall Secure External Channels - TLS Secure Logging Agent Secure Backend Infrastructure
  • 19. 192018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Limit the number of ECUs with off-board connections Restrict access to the network (I) Safety and Security Aspects of Automotive High Performance Controllers Today: multiple connections
  • 20. 202018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. • Divide network into security zones, e.g. extern, “demilitarized”, internal. • Restrict traffic between zones: Physical split or separation via VLANs: Not only extern-intern, but also intern-intern, e.g. infotainment to powertrain Restrict access to the network (II) Safety and Security Aspects of Automotive High Performance Controllers VLAN Tagging to separate external – internal • External frames are tagged with an orange VLAN tag at the switch • Only nodes assigned to the orange VLAN can receive frames from the external tester • Frames to be sent to external tester, are sent via the orange VLAN – the switch at the gateway removes the orange VLAN tags before forwarding it to the tester VLAN Tagging to separate internal networks • ECUs from Infotainment (blue VLAN), chassis (green VLAN) and powertrain (yellow VLAN) can be separated • Traffic between VLANs require a switch or Gateway Tester
  • 21. 212018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Example: Platform Security Layers Safety and Security Aspects of Automotive High Performance Controllers Operating Systems Containers Hardware Classic µC HSM Performance µP SwitchSecure EnginePerformance Cores Hypervisor Processes Resource Access Control Intermediate Address Space Separation (1st-Stage MMU) Control Flow Integrity Hardware Resource Separation Physical Address Space Separation 2nd-Stage MMU Scheduling Domains Resource Constraints Control Flow Integrity Virtual Address Space Crypto Accelerators 3 Core Logic (Secure, Public & PKA) Dedicated RAM/ROM (key material) eFuses Life Cycle Management Hardware Access Protection Crypto AcceleratorsHSM (EVITA medium) HIS SHE support DoS prevention VLAN Tagging Static ARP tables Monitoring Ports
  • 22. 2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Outlook
  • 23. 232018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. Outlook: Interesting Times... Safety and Security Aspects of Automotive High Performance Controllers machine learning crowed sourced data system of systems third party access personalization shortened development cycles evolution after SOP new topics new business models ?
  • 24. 2018-03-13 | Funktionale Sicherheit und Security in der Fahrzeugelektronik 2018 | Public | © Elektrobit Automotive GmbH 2018. All rights reserved, also regarding any disposal, exploitation, reproduction, editing, distribution, as well as in the event of applications for industrial property rights. www.elektrobit.com alexander.much@elektrobit.com Get in touch!