July 2018 Community Call
July 11th, 2018 11:00am
Justin Cappos, NYU and Sebastien Awwad, Uptane
Uptane is the first compromise-resilient software update security system for the automotive industry. Unlike other software update security systems (e.g., OMA-DM, SSL / TLS, signing updates with a single offline GPG / RSA key, etc.), it addresses a comprehensive threat model. It is designed to make it extremely difficult for attackers to be able to install malware on all vehicles maintained by a manufacturer, even if attackers have compromised some keys used to sign updates. At the same time, Uptane has been designed to be extremely flexible, so as to accommodate a wide variety of deployment scenarios, and allows on-demand customization of updates installed on vehicles.
Google document version of the Uptane slides: Uptane AUTO-ISAC 2018 Securing Over-the-Air Upd…