Vehicle software is increasingly being remotely updated through OTA (air download) technology. This approach allows for faster delivery of repairs and functional upgrades, and reduces the costs of recall and in-house maintenance. However, analysts pointed out that the deeper vehicles are connected to the network and the greater the potential for attack, the associated risks extending from data privacy to traffic safety and infrastructure security.
Tesla pushed OTA into business normal.
OTA technology can send software, solids, patches and data to network devices via wireless networks. The CNBC quoted researchers as saying that Tesla had sent remote updates to Model S since 2012, and that the model had gradually been widely accepted in the automobile industry and embedded in more models and systems.
Siraj Ahmed Shaikh, Professor of System Security, University of Swansea, United Kingdom, stated that OTP was faster and less expensive than traditional recall or regular maintenance and was therefore popular with the car company. However, while facilitation increases, it also means that more critical systems are permanently connected.
European test exposure to remote access hazard
The risk concerns are further amplified in the light of recent measurements. At the end of last year, the Norwegian bus company Ruter tested two buses and found that one of them had a potential risk associated with OTA.
According to Ruter, the vehicle's battery and power control system can be accessed through the mobile network and the connection path involves a Romanian SIM card. According to them, in theory, the manufacturer may suspend the vehicle or render it incapable of working.
This investigation subsequently prompted the United Kingdom and Denmark to conduct their respective investigations. The United Kingdom Department of Transport indicated that it was working closely with the National Cyber Security Centre to assess relevant issues.
Concerns have been extended from single manufacturers to industry levels
It was reported that the above-mentioned survey was carried out in connection with a bus made by China's AutoTechnology Corporation. However, according to the experts interviewed, the problem was not limited to a manufacturer or a country, but rather to the common risk that the OTA technology posed by the spread of transport.
According to Gabriel Lim, an analyst at the International Research Institute in Lajarnan, Singapore, such technologies constitute a unique national security concern. In addition to data privacy issues, the potential for outside actors to interfere with a moving vehicle control system has also attracted concerns in Norway, Denmark and the United Kingdom.
The U.S. Business Research Institute also proposed in May this year that, in order to limit the intelligence-gathering capacity of foreign governments, the United States should strengthen its car industry safety reviews and consider limiting some foreign-made vehicle hardware and hardware, while requiring businesses to disclose more data collection information.
It's not just the car.
Shaikh also pointed out that it was not just the automobile industry that used OTA. Similar capabilities are being introduced in maritime, rail, aerospace, especially drones, as well as industrial machinery and robots.
As the coverage of such systems expands, so does the examination of how they are deployed, of remote competencies and of the attribution of responsibilities. According to analysts, the key question is not just whether technology is convenient, but who can access the system, what can be done after access, and whether the relevant regulations are up to date.
