SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.

China opened comment on a mandatory standard for automotive cryptography

A draft mandatory national standard would require Chinese-market vehicles to use approved cryptography to verify software update packages, boot firmware in stages, and authenticate whoever writes calibration parameters through the diagnostic port.

China’s Ministry of Industry and Information Technology opened public comment on August 21 on a mandatory national standard covering cryptography in vehicles, with a deadline of October 20. The notice was published by the National Technical Committee of Auto Standardization, which is developing the standard under plan number 20243883-Q-339.

The draft, dated July 24, is titled Technical requirements for vehicle cryptography application. It applies to M- and N-category vehicles, and states that components implementing cryptographic functions on the vehicle may follow it as well. The document is jointly proposed by the ministry and the State Cryptography Administration, and requires that algorithms used in vehicles conform to national, industry or international cryptography standards and satisfy state cryptography management requirements.

Three clauses reach directly into vehicle software. Secure boot would be mandatory for remote control systems, the on-board software update system, the automated-driving data recording system, and any system a risk assessment identifies as needing it, with firmware, bootloader, operating system and key application software each verified in turn before loading. Update packages would have to be checked by digital signature or message authentication code — and where the on-board update system is not used, each controller would verify the package itself before loading it, unless the software update is performed in a trusted environment, which the draft defines as copying the package over a secure channel. Write commands sent through the diagnostic interface to change key configuration or calibration parameters would require the sending entity to be authenticated.

Vehicles would also have to reach telematics and update platforms over TLS 1.2 or later, or the Chinese TLCP protocol.

The draft sets a two-stage clock: new type approval applications would comply from the date the standard takes effect, and already-approved models from the twenty-fifth month after it.

Why it mattersChinese cybersecurity rules have so far described what has to be protected, and this one names the mechanism, the interfaces and the compliance clock — including a diagnostic-port requirement that reaches the aftermarket and the workshop, not just the carmaker.

Source: National Technical Committee of Auto Standardization

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.