International Cooperation to Secure Connected Vehicles
CIOREVIEW >> Oracle >> NEWS

NIO’s Advanced Research and Innovation Center

Dr. Yueqiang Cheng, Director, Head of Software Security & Tools

International Cooperation to Secure Connected Vehicles

Dr. Yueqiang Cheng, Director, Head of Software Security & Tools
Dr. Yueqiang Cheng, Director, Head of Software Security & Tools, NIO’s Advanced  Research and Innovation Center

I currently lead a product security team focused on highly innovative security research initiatives and architecture designs to further ensure NIO’s security.

Before joining NIO, I was a Senior Staff Security Scientist at Baidu Research and worked on system security, software security, and microarchitecture security. I was also a Postdoctoral Fellow at CMU CyLab with Professor Virgil Gligor.

I have published many high-quality papers at top-tier academic conferences and journals including ASPLOS, CCS, Usenix Security, NDSS, MICRO, ICSE, IEEE TDSC, IEEE TIFS), as well as industry conferences (e.g., BlackHat, Defcon, Bluehat, CanSecWest).

Based on this expertise I would say, unsurprisingly, connected vehicles are becoming increasingly attractive targets for cyber attackers due to the large amount of valuable data that can be accessed, as well as the potential safety risks posed by compromising vehicle systems. To address vehicle security threats, it is necessary to conduct comprehensive vulnerability and risk assessments, develop targeted security protection strategies, and deploy appropriate security solutions. This may involve a range of measures, including secure software development practices, network encryption, access control and authentication mechanisms, intrusion detection and prevention systems, and regular security audits and assessments.

Only vehicles holding both R155 CSMS and VTA model certifications are authorized for sale in the European Union. These certifications, along with the ISO/SAE 21434 CSMS certification obtained by NIO, ensure that the security of our products is maintained throughout their entire life cycle. This includes the conception, design, development, testing, production, and post-production stages, providing comprehensive security coverage and enhancing research and development efficiency. NIO is committed to delivering vehicles that meet the highest standards of safety and security.

NIO's robust research and development capabilities and advanced electric vehicle systems have been designed with elevated security levels to safeguard users and associated products from cyber security risks. Prompt and efficient responses are provided in the event of cyber security threats or attacks, ensuring that users' assets and personal security are protected.

Compliance with the R155 regulation is largely supported by the ISO21434 standard, which defines the complete framework for vehicle cyber security and related cyber security life cycle processes. As of July 2022, all newly marketed vehicle types in UN countries must possess both R155 CSMS and R155 VTA certifications. The R155 VTA certification requires specific work item reviews for cyber security development to ensure the successful implementation of cyber security protection technologies and mechanisms in vehicles.

  ​As the popularity of electric vehicles continues to rise, the need for a comprehensive cybersecurity protection mechanism has become increasingly crucial in safeguarding user safety  

Acquiring R156 SUMS certification guarantees alignment between the vehicle design and software update processes. The Software Update Management System (SUMS) ensures the security of vehicle software updates, eliminating security threats throughout the software update process, and ensuring the security of both the process and the software itself.

NIO has developed a comprehensive range of capabilities about security technology and research and development, which encompass the complete life cycle of automotive software and hardware development, vehicle production and operation, and maintenance. These capabilities include threat analysis, risk management, incident response, vulnerability management, vehicle security monitoring, supplier cyber security management, production line cyber security, vehicle after-sales security updates, and end-of-life management. This extensive set of capabilities ensures the continuous security and safety of NIO vehicles throughout their life cycle.

Moreover, NIO has implemented a comprehensive security defense system that covers cloud, channel, and endpoint security. This system comprises independently developed PKI (Public Key Infrastructure) systems, security diagnostic tools, data security systems, vehicle intrusion detection and defense systems, and other security products. Cloud security is maintained through strict access control policies, cloud firewalls, failover mechanisms, and off-site disaster recovery. The vehicle's onboard system is secured using VLAN networks, OBD firewalls, security OTA, access control, and data security protection. The mobile phone endpoint is secured through equipment certificates, APP reinforcement, PIN code verification, and login defense systems. Finally, communication channel security is ensured through APN network access, channel encryption, and other security measures.

NIO has proactively addressed these challenges by independently developing multiple security systems, including a data security system, a secure cloud service center, a vehicle IDS/IPS system, and security diagnostic tools. The data security system ensures the protection of sensitive data through desensitization processing, secure transmission, protected and trusted computation/analysis, encryption storage, and the whole lifecycle management. The secure cloud service center employs Public Key Infrastructure (PKI) technology and digital certificates to provide system information security services and verify the identity of digital certificate holders. Meanwhile, the onboard IDS/IPS system provides comprehensive monitoring and defense against cyber-attacks, and dedicated security diagnostic tools are used to diagnose vehicles.

As the popularity of electric vehicles continues to rise, the need for a comprehensive cybersecurity protection mechanism has become increasingly crucial in safeguarding user safety

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.