Close Menu
Automotive Testing Technology International
  • News
    • A-H
      • ADAS & CAVs
      • Aerodynamics
      • Appointments, Partnerships, Investments & Acquisitions
      • Automotive Testing Expo
      • Batteries & Powertrain Testing
      • Component Testing
      • Safety and crash testing
      • Dynamometers
      • EMC & Electronics Testing
      • Emissions & Fuel Consumption
      • Facilities
      • Full-vehicle Testing
    • I-Z
      • Interiors & Infotainment Testing
      • Measurement Tools, Test Systems & Equipment
      • Motorsport
      • NVH & Acoustics
      • Proving Grounds
      • R&D
      • Sensors & Transducers
      • CAE, Simulation & Modeling
      • Software Engineering & SDVs
      • Tire Testing
  • Features
  • Online Magazines
    • March 2025
    • November 2024
    • September 2024
    • June 2024
    • Crash Test Technology – 2023
    • Automotive Testing Technology
    • Subscribe to Automotive Testing
    • Crash Test Technology
    • Subscribe to Crash Test Technology
  • Opinion
  • Awards
    • About
    • What’s new and key dates
    • Eligibility and nomination
    • Get in touch
    • Judges
    • Winner interviews
  • Videos
  • Supplier Spotlight
  • Proving Grounds
  • Events
LinkedIn Facebook X (Twitter)
  • Automotive Interiors
  • Automotive Powertrain
  • ADAS & Autonomous Vehicle
  • Professional Motorsport
  • Tire Technology
  • Media Pack
    • 2026 Media Pack
    • 2025 Media Pack
LinkedIn
Subscribe
Automotive Testing Technology International
  • News
      • ADAS & CAVs
      • Aerodynamics
      • Appointments, Partnerships, Investments & Acquisitions
      • Automotive Testing Expo
      • Batteries & Powertrain Testing
      • Component Testing
      • Safety and crash testing
      • Dynamometers
      • EMC & Electronics Testing
      • Emissions & Fuel Consumption
      • Facilities
      • Full-vehicle Testing
      • Interiors & Infotainment Testing
      • Measurement Tools, Test Systems & Equipment
      • Motorsport
      • NVH & Acoustics
      • Proving Grounds
      • R&D
      • Sensors & Transducers
      • CAE, Simulation & Modeling
      • Software Engineering & SDVs
      • Tire Testing
  • Features
  • Online Magazines
    1. March 2025
    2. November 2024
    3. Crash Test Technology – 2024
    4. September 2024
    5. June 2024
    6. Automotive Testing Technology
    7. Subscribe to Automotive Testing
    8. Crash Test Technology
    9. Subscribe to Crash Test Technology
    Featured
    April 9, 2025

    In this Issue – March 2025

    Automotive Testing Technology By Rachel Evans
    Recent

    In this Issue – March 2025

    April 9, 2025

    In this Issue – November 2024

    November 26, 2024

    In this Issue – 2024

    September 30, 2024
  • Opinion
  • Awards
    • About
    • What’s new and key dates
    • Eligibility and nomination
    • Get in touch
    • Judges
    • Winner interviews
    • ATTI Awards Forum
  • Videos
  • Supplier Spotlight
  • Proving Grounds
  • Events
LinkedIn
Subscribe
Automotive Testing Technology International
Industry Opinion

Security alert

Cesare Garlati, chief security strategist, prpl FoundationBy Cesare Garlati, chief security strategist, prpl FoundationOctober 18, 20163 Mins Read
Share LinkedIn Twitter Facebook Email

When it comes to testing the components of modern connected cars, of course pen-testing (penetration testing) has its place; however, it is no substitute for solid product development.

In testing, companies often operate under the notion that an identified problem can be fixed or patched. This may be true for some areas of testing, but for security, it is not sufficient. Security needs to be built-in, from the ground up. And that means starting at the hardware layer, which is seldom done today, but which is completely viable given the advancements in silicon and other connected vehicle technologies.

In fact, the prpl Foundation has produced a guide on how to secure critical areas of embedded computing that advocates the use of open, interoperable protocols and APIs, exercising security by separation, through implementing hardware virtualization and anchoring a root of trust in silicon.

Looking back at all of the recent public cases of researchers hacking connected cars, they all share the exploitation of proprietary code. This idea that closed, proprietary systems can work within Internet of Things and connected devices is a myth. In contrast, an open security framework means it has constantly been tested and had many eyes cast over it to ensure its strength.

The second thing they all have in common is that once hackers were able to reverse engineer vendor-specific code to gain access to one area of the system, they proceeded to move around laterally to other networked components. This idea that once an actor can gain access to a non-critical component in a vehicle, such as the entertainment system, and then work their way into a critical area, such as the steering, is scary to think about. But without using the time tested method of security by separation, it is a reality. This separation can be achieved by using hardware virtualization so that although independently they might not be more secure, as a system, one bad apple doesn’t compromise the whole system.

Finally, all of these security controls need to be tied to a root of trust in silicon; this can be a by-product of the hypervisor used in creating hardware virtualization or by some other method. One neat area being explored by prpl at the moment is physical unclonable function (PUF) technology that can extract a unique identifier from the silicon itself, much like a fingerprint, to provide authentication and establish a root of trust.

In summary, pen-testing is important, but it is no replacement for sound product development. Security can only be forged from the ground up in the silicon of connected components themselves. It cannot be added as an afterthought as we have seen time and time again. Testing alone does not make a product secure. From a risk management perspective, testing lowers the risk but doesn’t completely remove it. After all, upon successful testing one can say, “I couldn’t find anything wrong,” which is not the same as saying, “There is nothing wrong.”

Cesare Garlati, formerly VP of mobile security at Trend Micro, currently serves as chief security strategist at prpl Foundation and co-chair of the mobile working group at Cloud Security Alliance.

Prior to Trend Micro, Garlati held director positions within leading mobility companies such as iPass, Smith Micro Software and WaveMarket. Before this, he was senior manager of product development at Oracle, where he led the development of Oracle’s first cloud application and many other modules of the Oracle E-Business Suite.

October 18, 2016

Share. Twitter LinkedIn Facebook Email
Previous ArticleDesigning trucks for platooning
Next Article Advanced speed warning system under development at Ford
Cesare Garlati, chief security strategist, prpl Foundation

Related Posts

Active Safety

Reengineering mobility: The SDV revolution beyond CASE

June 12, 20258 Mins Read
Cybersecurity

Five approaches to vehicle testing

June 10, 20254 Mins Read
Full-vehicle Testing

Transforming automotive time-to-market – Now or never for traditional auto makers

April 10, 20257 Mins Read
Latest News

Rohde & Schwarz unveils FSWX signal analyzer with innovative multi-path architecture

June 16, 2025

GM’s Pramod Kumar named president of Open Alliance

June 16, 2025

MB Dynamics develops lightweight shaker for testing on the move

June 16, 2025
Free Weekly E-Newsletter

Receive breaking stories and features in your inbox each week, for free


Enter your email address:


Our Social Channels
  • LinkedIn
Getting in Touch
  • Free Weekly E-Newsletter
  • Meet the Editors
  • Contact Us
  • Media Pack
    • 2026 Media Pack
    • 2025 Media Pack
RELATED UKI TITLES
  • Automotive Interiors
  • Automotive Powertrain
  • ADAS & Autonomous Vehicle
  • Professional Motorsport
  • Tire Technology
  • Media Pack
    • 2026 Media Pack
    • 2025 Media Pack
© 2025 UKi Media & Events a division of UKIP Media & Events Ltd
  • Terms and Conditions
  • Privacy Policy
  • Cookie Policy
  • Notice & Takedown Policy
  • Site FAQs

Type above and press Enter to search. Press Esc to cancel.

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.

CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.

Functional

Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.

Performance

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

Analytics

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.

Advertisement

Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.

Others

Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.

SAVE & ACCEPT