Design of Information Security Solution for OTA Upgrade of Commercial Vehicles
Wang Ruichao, Wei Wei, Qin Yanlong, Zhao Yifan
Author information+
Foton Daimler Automotive Co., Ltd., Beijing 101499, China
Show less
文章历史+
收稿日期
出版日期
2025-05-12
2026-01-20
发布日期
2026-01-20
摘要
随着汽车“新四化”的发展,汽车软件更新迭代频繁,传统的离线升级功能已无法满足用户及车企需求,因此需要开发汽车远程空中下载(Over the air,OTA)升级功能。通过 OTA 升级,车企可实时向车辆推送新功能,持续优化用户的产品体验。然而,OTA 升级过程涉及车端、云端、通信链路多环节的数据交互,使车辆面临网络攻击的风险。本文从升级包安全、车云链路安全、车端安全存储及安全监测与应急响应四个维度,系统介绍商用汽车 OTA 功能开发中的信息安全应对方案,为商用汽车 OTA 安全落地提供技术参考。
Abstract
With the development of the "new four modernizations" of automobiles, automotive software is updated and iterated frequently. The traditional offline upgrade function can no longer meet the needs of users and automakers. Therefore, it is necessary to develop the over-the-air (OTA) upgrade function for automobiles. Through OTA upgrades, car manufacturers can push new features to vehicles in real time and continuously optimize the user product experience. However, the OTA upgrade process involves data interaction among multiple links such as the vehicle end, cloud, and communication links, exposing the vehicle to the risk of cyber attacks. This article systematically introduces the information security response solutions in the development of OTA functions for commercial vehicles from four dimensions: upgrade package security, vehicle-cloud link security, vehicle-end secure storage, and security monitoring and emergency response, providing technical references for the secure implementation of OTA in commercial vehicles.
Wang Ruichao, Wei Wei, Qin Yanlong, Zhao Yifan.
Design of Information Security Solution for OTA Upgrade of Commercial Vehicles[J]. AUTO ELECTRIC PARTS. 2026, 1(1): 48-50