Connected Cars: Security Challenges in the Automotive Industry

Connected Cars: Security Challenges in the Automotive Industry

Breakthroughs in technology mean that connected cars are shunning physical keys in favor of digital, smartphone-based entry systems.

Connected cars are a major talking point in the automotive industry right now. Essentially, these cars are connected to the internet, and are usually full of interesting technology. In fact, the car industry is increasingly collaborating more with technology companies like Microsoft, to help further develop connected cars.

Breakthroughs in technology mean that connected cars are shunning physical keys in favor of digital, smartphone-based entry systems.

Whilst this new technology is exciting, it raises security questions from car owners, which the automotive industry must answer. This presents a major challenge for us: not only do we need to ensure that security is high, we also have to educate customers. After all, why should they buy a product they don’t trust?

We look at some of the key security challenges the automotive industry currently face, and what we can do to solve these.

Customer concerns on digital security

As is the case with new technology, security concerns often arise. One major question customers have is: just how safe are digitized car keys?

In order to overcome this challenge, we need to educate customers on what they can do to maximize security. Firstly, advise them that as virtual car keys must be stored on their smartphone, they should treat this with the same level of security as they would their online banking.

Letting customers know that strong authentication and prior registration are both necessary, will help to contribute towards better security. Plus, as security of mobile apps are still a cause for concern, inform customers that they should store their virtual key within their phone’s internal NFC secure element.

Oberthur Technologies, a firm specializing in embedded digital security, recommended that for the most robust form of authentication, biometrics may be used to link the user’s identity with their phone, and therefore their car keys.

The only way in which we as an industry can help tackle this challenge is by raising awareness of the ways in which customers can help their connected cars stay secure.

Customer concerns on car theft

Criminal gangs are using hi-tech equipment to re-program car keys. By manipulating the wireless signals used by car keys, they can start the vehicle.

Naturally, this is a big concern amongst customers, and is another challenge that the automotive industry must tackle.

Unfortunately, this type of car theft is fairly common. In 2015, 42% of all London car thefts were carried out in this way, with higher end vehicles including the BMW 3 Series, Audi Q7 and Range Rover hit the hardest.

There are two main ways in which criminals can steal connected cars. The first is an amplification attack, whereby technology is used to alter the radio frequencies used by car keys. Essentially, criminals can trick car systems into thinking the owner is nearby with the key, meaning they can enter the car and start the engine. 

Criminals could even steal a car if the key fob is nearby – all they have to do is try the door. Alternatively, if the signal from a wireless key fob is jammed, the owner may walk away thinking they’ve locked the car when in fact, they haven’t. While the car can’t be driven away without a key, it enables criminals to steal the contents. It’s an understandable concern that needs addressing.

So how do we face this challenge? Firstly, it’s worth remembering that whilst keyless car thefts have risen over the last few years, overall car crime in the UK has dropped by 75% in the past decade.

Inform customers to follow basic safety recommendations – parking in a secure, well-lit area, using a steering wheel lock and even fitting an immobilizer – all of which will help to prevent their cars from being stolen.

The rise in digital hacking

Whilst car theft poses a problem, police have warned that cars with keyless entry will remain vulnerable if hackers can crack the codes.

This presents the other major challenge for the automotive industry, as manufacturers are constantly trying to update car security whilst hackers are attempting to find ways around it.

When manufacturing cars, one component may be secure, but when another component is then thrown into the mix, a weakness is added.

To help combat this challenge, a baseline level of security should be introduced into the automotive industry, so that the threat of cybersecurity is always reduced.

The other potential issue in this area is with over-the-air (OTA) software updates. 4.6 million cars currently receive OTA updates, and this is expected to increase to 43 million by 2022. This drastically heightens the challenge of cyber security.

What can we as an industry do about this? Whilst unfortunately we can’t wipe out hackers, by testing the technology ourselves and trying to crack the code, we can then figure out the best ways in which to stop criminals from doing the same thing. Only by doing this ourselves can we find out which areas of our products are most vulnerable to attack.

The ever-evolving technology in connected cars is exciting, but is not without its challenges. Therefore, it’s imperative that as an industry we address these challenges head-on so that we can celebrate the success we’re experiencing in technology.

To learn more, visit CAT Autokeys at http://www.catautokeys.co.uk/.

Featured

  • 91 Percent of Security Leaders Believe AI Set to Outpace Security Teams

    Bugcrowd recently released its “Inside the Mind of a CISO” report, which surveyed hundreds of security leaders around the globe to uncover their perception on AI threats, their top priorities and evolving roles, and common myths directed towards the CISO. Among the findings, 1 in 3 respondents (33%) believed that at least half of companies are willing to sacrifice their customers’ long-term privacy or security to save money. Read Now

  • Milestone Announces Merger With Arcules

    Global video technology company Milestone Systems is pleased to announce that effective July 1, 2024, it will merge with the cloud-based video surveillance solutions provider, Arcules. Read Now

  • Organizations Struggle with Outdated Security Approaches, While Online Threats Increase

    Cloudflare Inc, recently published its State of Application Security 2024 Report. Findings from this year's report reveal that security teams are struggling to keep pace with the risks posed by organizations’ dependency on modern applications—the technology that underpins all of today’s most used sites. The report underscores that the volume of threats stemming from issues in the software supply chain, increasing number of distributed denial of service (DDoS) attacks and malicious bots, often exceed the resources of dedicated application security teams. Read Now

  • Cloud Resources Have Become Biggest Targets for Cyberattacks According to New Research

    Thales recently announced the release of the 2024 Thales Cloud Security Study, its annual assessment on the latest cloud security threats, trends and emerging risks based on a survey of nearly 3000 IT and security professionals across 18 countries in 37 industries. As the use of the cloud continues to be strategically vital to many organizations, cloud resources have become the biggest targets for cyber-attacks, with SaaS applications (31%), Cloud Storage (30%) and Cloud Management Infrastructure (26%) cited as the leading categories of attack. As a result, protecting cloud environments has risen as the top security priority ahead of all other security disciplines. Read Now

Featured Cybersecurity

Webinars

Whitepapers

New Products

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Automatic Systems V07

    Automatic Systems V07

    Automatic Systems, an industry-leading manufacturer of pedestrian and vehicle secure entrance control access systems, is pleased to announce the release of its groundbreaking V07 software. The V07 software update is designed specifically to address cybersecurity concerns and will ensure the integrity and confidentiality of Automatic Systems applications. With the new V07 software, updates will be delivered by means of an encrypted file. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3