Solutions

Protecting Vehicles from Internet-Based Attacks to Ensure They Stay Safe and Convenient Connected Car Security

Many of the things we use in our daily lives are now connected to the Internet, and automobiles are no exception. Connected cars, which function as IoT devices, collect a wide range of data over networks, including vehicle status and surrounding road conditions. By analyzing and utilizing this data, they can enhance driver safety and convenience and provide a more efficient driving experience. As a result, connected cars are attracting significant attention as the automobiles of the near future. However, being connected to a network also means that connected cars are exposed to the risk of being targeted by hackers. As connected vehicles become more sophisticated, the number of potential security risk points continues to increase, including ECUs, in-vehicle networks, infotainment systems, authentication systems, and smartphones and AI devices that interact with the vehicle. The greatest risk associated with connected cars is the potential loss of human life. For this reason, connected cars require a very high level of information security.

Asgent’s Connected Car Security Approach

  • Establishing a security framework

    Establishing a security framework is also crucial for organizations involved in the development and design of connected cars. It is necessary to identify the security risks surrounding the connected car solutions – including the organizational structure – and implement measures appropriate to those risks.
    In the automotive industry and other IoT domains, the key to a security governance framework is the ISMS (Information Security Management System) approach. Since its founding, Asgent has been deeply involved with ISO/IEC 27001, providing not only certification support but also consulting services to a wide range of organizations. Drawing on this experience, we help build strong security frameworks that take into account the specific requirements and regulations of the automotive industry.

セーフティとセキュリティの国際規格の策定情報
Services
Key features of the Connected Car Security Services (tentative name)
  • Strategic Advisory Services by Consultants with Deep Expertise in ISO/IEC 27001
  • Development of Custom Security Frameworks Tailored to Customer-Specific Regulations and Internal Standards
  • Establish “Security-by-Design” Processes Integrated into Every Phase of the Product Lifecycle
Connected Car
Security Services (tentative name)
Security Services
  • ECU Security

    Vehicles are equipped with numerous ECUs (Electronic Control Units), which control a wide range of functions such as the engine, brakes, and door locks. By sending unauthorized messages to an ECU, an attacker could potentially take control of functions such as braking or acceleration. For this reason, ECUs require dedicated security measures. In addition, unlike conventional IT systems, ECUs must operate in real time, which places strict constraints on security mechanisms—for example, intrusion detection cannot take a long time to complete. Asgent’s ECU security solution, XGuard Integrity, applies security directly to the ECU during the manufacturing process. It protects against hacking without the false positives that can occur with other security products. In addition, because it does not require security updates and imposes extremely low overhead during operation, it helps prevent serious security risks before they can materialize.

Products
Key features of XGuard Integrity
  • Zero false positives
  • No security expertise required for IoT device or software developers
  • No security updates required
  • Independent of OS and CPU

Learn More
XGuard Integrity
Karamba
  • In-vehicle network authentication

    The ECUs installed in a vehicle are connected through a CAN (Controller Area Network), which enables the exchange of data used to control a wide range of functions, including the engine, transmission, brakes, and air conditioning. To protect vehicles from physical hacking and unauthorized communications sent from unapproved ECUs, it is therefore necessary to authenticate in-vehicle communications and ensure their security. However, in-vehicle networks are already heavily utilized, leaving little capacity to process additional authentication data that would consume network throughput. Asgent’s authentication solution, SafeCAN, introduces no network overhead, enabling CAN bus communications to be authenticated without imposing excessive load.

Services
Key features of SafeCAN
  • Authenticates communications without imposing excessive overhead
  • Enables secure OTA updates
Learn More
SafeCAN
Karamba
  • Hardening mobile applications

    Mobile devices are becoming indispensable to connected cars, for example by enabling users to operate in-vehicle infotainment systems from their smartphones. For this reason, mobile applications need to be hardened against attacks. Asgent’s solution applies various protection measures when applications are built, including code obfuscation and string encryption. In addition, multiple mechanisms are incorporated to detect and prevent attacks, helping to create robust applications that are difficult to compromise.

Products
Key features of Application Protection
  • Provide robust mobile applications
  • Protects against reverse engineering
  • Prevent information leakage
Learn More
Application Protection
(formerly Arxan EnsureIT/GuardIT)
Digital.ai