Telemetries and Data | ISO/SAE 21434 and WP.29 CSMS

TEAM UPSTREAM

Collecting vehicle telemetries and vehicle data is super-important for securing the vehicle in post-production. The reason is that in post-production, we need to protect the vehicle against attacks that were known at the time of the vehicle development, but also against new attacks that were unknown while the vehicle was developed. And these new attacks are result of new attack techniques and new services that are being introduced to the market.

This is why CSMS actually requires the OEM to detect cyber attacks based on vehicle logs. And if you look specifically
at the requirement, in CSMS, it’s required to have detection, a centralized detection system that is based on vehicle logs, detects cyber attacks, and provides a response within a reasonable timeframe to these attacks.

In the Vehicle Type requirements, it’s required to secure critical elements in the vehicle, but also to emit meaningful telemetry that will enable this type of post-production detection for vehicles while they’re on the road.

And when you combine these two requirements, you get a very powerful way to detect attacks in a centralized manner as
part of the management system.

So, such a detection system really enables a very broad coverage of the threats listed in Annex 5 of the WP.29, but also because you collect telemetries from millions of vehicles, you really can create a very strong baseline that describes the normal
behavior of the vehicle and have an effective anomaly detection system that can also help detect unknown attacks.

Lastly, when you collect lots of telemetries, you can not only detect the attack, but you can apply forensics and really detect the root cause of the attack.

Newsletter Icon

Subscribe
to our newsletter

Stay up-to-date on the latest trends, emerging risks, and updates

Sécuriser et renforcer l’avenir de la mobilité et de l’IoT

Upstream libère le potentiel des véhicules connectés, de l’IoT et des données de la mobilité intelligente. 
 Sa plateforme de gestion des données est spécialement…

More Details

Études de cas : Comment l’IA permet de détecter plus tôt les problèmes de qualité véhicule

La détection proactive de la qualité (PQD) d’Upstream en action, accélérant l’analyse des causes premières (RCA), l’évaluation de la gravité et la priorisation des problèmes…

More Details

Beyond the Cyber Resilience Act: Building
Cyber Resilience for the EV Charging Ecosystem

The CRA places broad obligations on manufacturers, including those who design, develop, or brand charge points, backend systems, and embedded communication software used throughout the…

More Details

Beyond the Cyber Resilience Act: Building Holistic Cyber Resilience

A decade ago, the value of connected vehicle data was associated with new revenue streams for OEMs. Fast forward to today, a more effective and…

More Details

Tech Talk: Securing the Commercial Fleet Ecosystem with IVECO’s CISO

The commercial vehicle industry is undergoing a seismic shift. The convergence of connectivity, electrification, and software-defined vehicles is unlocking unprecedented efficiency but also exposing f

More Details

Unmasking the Blind Spot: Why API Security Is the Weak Link in Automotive Cybersecurity

In this session, recorded during the Auto ISAC Partners Week, Upstream's Dr. Matthias Lenk and Fabian Stahl explain why API security remains a critical yet…

More Details
Skip to content