Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

The drive to 2015 CES — first stop: Connected Car Conference

Derek Kuhn
The 2015 International CES show is just 6 months away. As a preview of what we’ll see in January, the Consumer Electronics Association (CEA) recently held its annual CEWeek, which included a special half-day event focused on the connected car and its influence on consumers’ lives.

Chaired by industry veteran Doug Newcomb, the Connected Car Conference (C3) explored some of the most pressing trends for connected automotive technology, including distracted driving, the Internet of Things, and the possibility of a self-driving future.

I took part in the panel discussion on safeguarding driver privacy. Moderated by Roger Lanctot of Strategy Analytics, the panel also included representatives from AVG Technologies, Covisint, HARMAN, and the Intelligent Car Coalition.

The panel covered both security and privacy — two different but intimately related topics — and sparked a lively exchange that ran the gamut from key fobs and VIN numbers to software practices and regulatory agencies. Check it out:



The countdown to 2015 CES has officially started. I’ll see you in Vegas — in 183 days!

Klocwork joins QNX automotive safety ecosystem

Paul Leroux
This just in: Klocwork, a leader in development tools for creating secure software, has become an ecosystem partner for the QNX Automotive Safety Program for ISO 26262.

Klocwork joins a roster of companies, including Elektrobit, Freescale, NVIDIA, and TI, who already support the program, which is designed to help automotive companies build digital instrument clusters, ADAS systems, and other products with functional safety requirements.

Klocwork offers Insight, a source code analysis tool recently certified to the ISO 26262 and IEC 61508 functional safety standards. Insight plugs directly into the QNX Momentics Tool Suite, allowing developers to detect security and safety vulnerabilities on the fly, and to ensure their code meets functional safety standards.

"Klocwork Insight provides real-time feedback during code development, immediately alerting developers to code that may conflict with the MISRA C/C++ coding standards required by ISO 26262," said Grant Courville, director of product management at QNX. "Better yet, Insight plugs into our IDE to provide a seamless and productive development experience."

The QNX Automotive Safety Program for ISO 26262 was created to help automotive companies building functional safety products to leverage QNX Software Systems’ proven competency in certifications, safety-critical systems, and automotive software design. Key elements of the program include an example safety case based on the QNX Neutrino RTOS Safe Kernel, guidelines on safety-critical design for real-time OS-based systems, a suite of professional services, and an ecosystem of supporting vendors who offer complementary hardware, tool chains, graphics technologies, and consulting services for safety critical systems.

Read the press release.

Cyber security and connected cars

What does cyber security mean, what does it affect, why is it becoming critical, and what can you do about it? Those were some of the questions I addressed in a recent webcast on automotive cyber security, hosted by SAE International. I represented the software side of things and was accompanied by my hardware colleagues Richard Soja and Jeffrey Kelley, who work at Freescale and Infineon respectively.

I’ve hosted webinars on a variety of automotive and embedded software topics, but none with such an impressive range of participants. We had people from government organizations of several countries, not to mention automakers, tier 1 and tier 2 auto suppliers, telematics companies, mobile developers, concerned individuals, and even utility companies. And the range of questions and comments was equally diverse — from specific insights about elliptical encryption to sweeping “how does this affect society” musings.

My key takeaway: QNX isn’t alone in its concern for automotive cyber security. We have years of experience in building secure trusted systems and we’re excited to help customers build tomorrow’s secure cars. Nice thing is, the rest of the world is starting to get on board as well.

If you're interested, you can download the archived version of the webinar.

Goodbye passwords, hello biometrics

Let's face it — passwords suck.

Every day we have to recall all manner of alphanumeric combinations for bank PINs, network log-ons, corporate email, social networking, and e-commerce. According to Microsoft Research, the average user types eight passwords per day.

During a talk at last year's SAE Convergence, Joseph Carra from the US Department of Transportation said, “Passwords have to go” ... a breath of fresh air for those of us who rely heavily on the "forgot password" option. The stage is set, according to Carra, for biometrics to replace passwords in the vehicle.

Using biometrics for driver preferences is nothing new — my favorite example is a car seat that can identify you by the shape of your butt — but using them to replace passwords makes perfect sense.

Ultrasound fingerprinting, iris scans, facial recognition, signature dynamics, voice recognition, keystroke dynamics, hand geometry, skin patterns, and foot dynamics are already being used in enterprise security, law enforcement, border control, ATM transactions, and so on. And second-gen biometrics promise to pump up the Sci-Fi factor with neural wave analysis, electro-physiological biometrics, skin luminescence, body odor, and so on.

Many technologies eventually find their way into the car after becoming popular elsewhere — mobile telephony, media players, GPS navigation, etc. I can’t think of too many world-changing technologies that got their start inside the car. But given the innovative trajectory of today’s auto industry, that may be about to change.