Uppsats

Cybersecurity in vehicular over-the-air update systems : A systematic literature review

Master-uppsats

Högskolan i Skövde/Institutionen för informationsteknologi

Publicerad: 2026

Språk: Engelska

Sammanfattning

Modern vehicles run on software. Braking, steering, driver assistance, and even door locking all depend on code, and a new passenger car may carry more than 100 million lines of it. When that code needs fixing, manufacturers increasingly distribute patches wirelessly through over-the-air (OTA) updates rather than physical recalls. However, the same wireless channel that delivers a security fix can also be exploited, and the OTA chain presents a long attack surface: backend servers, cellular links, in-vehicle gateways, and individual control units each offer a point of entry. Man-in-the-middle interception, replay of outdated firmware, rollback to vulnerable versions, and firmware tam-pering have all been documented, and a 2024 formal analysis of the Uptane framework, widely regarded as the most trusted OTA security standard, surfaced six previously undetected flaws. Regulators have responded with legally binding requirements. UNECE R155 and R156, ISO 24089, ISO/SAE 21434, and China's GB 44495/44496 now govern how vehicle software must be secured and updated across most major markets. What has been missing is a methodologically transparent synthesis of the academic research that could inform compliance efforts. Existing OTA surveys rely on narrative methods without documented search protocols, and PRISMA-compliant automotive reviews have not targeted OTA specifically. This thesis addresses that gap. Six databases were searched for peer-reviewed work published between 2018 and March 2026; 1,299 unique records were screened; and after quality assessment and a post-hoc narrowing to the post-regulation period (2021 to 2026), fifty studies were retained for in-depth analysis. The review produces a threat-countermeasure map and a regulatory coverage matrix, both of which surface a pattern that prior surveys were not positioned to detect: research has concentrated heavily on se-curing the delivery of updates, while operational requirements such as update failure handling, post-update verifi-cation, and continuous monitoring are each addressed by no more than three studies.

Information

Författare
Alaaraj, Aiham
Lärosäte / institution
Högskolan i Skövde/Institutionen för informationsteknologi
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.