My Account Log in

1 option

A Dynamic Cybersecurity Benchmarking Framework for Automotive Cyber-Physical Systems Automotive Research Association of India

SAE Technical Papers (1906-current) Available online

View online
Format:
Book
Conference/Event
Author/Creator:
Shah, Ravindra, author.
Contributor:
Awasthi, Vibhu Vaibhav
Karle, Ujjwala
Conference Name:
Symposium on International Automotive Technology (2026) (2026-01-28 : Pune, India)
Language:
English
Physical Description:
1 online resource cm
Place of Publication:
Warrendale, PA SAE International 2026
Summary:
The modern vehicle is no longer a mechanical applianceit has transformed into a software-defined cyber-physical system, integrating OTA updates, cloud-connected diagnostics, V2X services, and telematics-driven personalization. While this evolution promises unprecedented value in consumer experience and fleet operations, it also surfaces a dramatically expanded and evolving attack perimeter, especially across safety-critical ECUs and communication buses. Cyber vulnerabilities have shifted from isolated IT threats to real-time, embedded exploits. Controller area network (CAN), the backbone of vehicle bus systems, remains intrinsically insecure due to its lack of authentication and encryption, making it highly susceptible to message injection and denial-of-service by low-cost tools. Similarly, OEM implementations of BLE-based passive entry systems have proven vulnerable to replay and spoofing attacks with minimal hardware.In the Indian context, the transition to connected mobility is advancing rapidly under national mandates such as FAME II, PM e-DRIVE, and the National Electric Mobility Mission Plan (NEMMP). However, field-level assessments of Indian and international vehicle modelsincluding ICE cars, electric two-wheelers, and fleet EVsreveal critical gaps in CAN architecture connected to critical ECUs, Cloud API and Endpoints and RF controls. Notably, many of these vulnerabilities materialized after vehicle homologation, propagating through OTA updates or third-party app integrations. This reality underscores the inadequacy of static, pre-market cybersecurity assessments in effectively mitigating operational risk. This paper introduces a novel, scalable methodology that addresses this critical gap by enabling empirical, attack-informed validation, aligned with both Indian priorities and international best practices
Notes:
Vendor supplied data
Publisher Number:
2026-26-0612
Access Restriction:
Restricted for use by site license

The Penn Libraries is committed to describing library materials using current, accurate, and responsible language. If you discover outdated or inaccurate language, please fill out this feedback form to report it and suggest alternative language.

Find

Home Release notes

My Account

Shelf Request an item Bookmarks Fines and fees Settings

Guides

Using the Find catalog Using Articles+ Using your account