Skip to main content
AutoSec Innovation

Update integrity

Software Update Management and Secure Over-the-Air Delivery

Define the processes, technical controls, and evidence needed to deliver vehicle software updates securely and demonstrably across the fleet lifecycle.
Secure software update integrity workflow

At a glance

  • Development
  • Production
  • Operations
  • Updates
Standards referenced
UNECE R156ISO 24089ISO/SAE 21434
Core deliverables
  • SUMS process documentation
  • Update security control specification
  • Impact assessment procedure
  • Delivery-path review findings

The problem we are asked to solve

  • Update processes exist in engineering but are not documented as a managed system.
  • Integrity and authenticity controls are inconsistent across ECUs.
  • Update impact on safety and configuration is assessed informally.
  • Field campaign evidence is difficult to reconstruct.

What changes as a result

  • A documented software update management system
  • Consistent integrity and authenticity controls across targets
  • Impact assessment integrated into release decisions
  • Traceable campaign records for regulatory and internal review

Scope of work

What the engagement covers

Scope is agreed per programme. These are the activities we most often deliver for this service.

  • Software update management system (SUMS) definition
  • Update process and role mapping
  • Update integrity and authenticity controls
  • Configuration and dependency management support
  • Impact assessment method
  • Backend and delivery-path security review
  • Campaign evidence framework
  • Supplier alignment for update responsibilities

Engagement methodology

How we work

A predictable sequence, adapted to your process and release gates rather than replacing them.

  1. 01

    Map the current process

    Trace how updates are built, approved, delivered, and confirmed today, including supplier contributions.

  2. 02

    Define the management system

    Document roles, decision points, and records so the process is reconstructable after the fact.

  3. 03

    Review technical controls

    Assess integrity, authenticity, rollback, configuration dependencies, and key lifecycle across targets.

  4. 04

    Establish impact assessment

    Set a repeatable method for judging safety, type-approval, and behavioural impact of a proposed update.

  5. 05

    Prove the evidence chain

    Run the process against a real or rehearsed campaign and confirm the records it produces are sufficient.

Deliverables

Every engagement ends with artefacts your organisation owns and can defend in review.

  • SUMS process documentation
  • Update security control specification
  • Impact assessment procedure
  • Delivery-path review findings
  • Evidence and record framework
  • Improvement roadmap

Relevant standards

We help organisations interpret and implement these requirements. We do not certify or approve organisations.

  • UNECE R156
  • ISO 24089
  • ISO/SAE 21434

Typical use cases

  • Preparing a software update management system for assessment
  • Securing an over-the-air update path end to end
  • Aligning update responsibilities with suppliers
  • Reviewing update integrity for a new ECU generation

Evidence

Case studies covering SUMS and Secure Updates work are being prepared for publication. Automotive security engagements are normally confidential, so we discuss comparable scope, method, and deliverables directly rather than publishing unverifiable claims.

Questions

Frequently asked

Is this only relevant for over-the-air updates?
No. Update management covers workshop, diagnostic, and over-the-air delivery. The controls and evidence differ, but the management system covers all paths.
How does this relate to ISO 24089?
ISO 24089 provides engineering practice for software update engineering. We use it to structure technical activities that support update management obligations.

Discuss Your Cybersecurity Program

Tell us where the programme is today and we will outline a realistic next step.