New road safety standards create trade-off with CAV cybersecurity

Terence Broderick

A busy city intersection at night with digital security graphics overlaying the scene, including a large padlock and radar-like target symbols.

As new safety features that require the collection of data from connected and autonomous vehicles (CAVs) continue to be introduced, a trade-off is developing between road safety and cybersecurity. Here, we highlight the new standards set to come into play during 2022 and explore the innovative solutions designed to protect driver safety in both the physical and digital realms.

A step change in vehicle safety

This year, a raft of safety features is set to become mandatory on new vehicles. While many of these are already standard on some vehicles, including drowsiness and attention detection systems, event data recorders and lane-keeping assistance, their mandatory introduction is seen as a step change in safety requirements.

Vehicle cybersecurity is seen as a key challenge in the automotive sector, said to present challenges that extend way beyond those in IT. This is largely due to the amount of data generated by and processed within road vehicles, which attracts a wide variety of threats. Such threats often don’t need to be directed at vehicles’ central systems to cause problems for drivers.

A step change in data collection

Since 2019, the European Data Protection Board (EDPB) has sought consultation for ‘guidelines on processing personal data in the context of connected vehicles and mobility related applications’. The purpose is to highlight where data privacy risks lie within vehicles as they become ever more connected, which will lead to the creation of guidelines designed to combat the risk of increased personal data collection.

It’s inevitable that new safety features require data on drivers and passengers that could be considered personal. This includes risky categories of data such as location, biometrics and data that could reveal offences or traffic violations (which are highlighted by the guidelines proposed by the EDPB consultation).

Road safety vs cyber risks

Such data may be attractive to cyber-criminals, who often look for opportunities to extort. For manufacturers, the challenge lies in decreasing their vehicles’ exposure to hackers while improving safety and being required to follow relevant guidelines.

Innovation around the management of the data generated and processed by vehicles will already be well underway and it remains to be seen which solutions will be most well adopted.

One of the biggest problems with addressing the wider challenge of automotive cybersecurity is the vast difference between automotive product life cycles and the substantially faster evolution of cyber threats. While a vehicle may be expected to be used for up to 20 years after first purchase, cyber threats evolve daily.

This places importance on effective software (able to respond to threats in real-time) and hardware (to support software updates), as well as over-the-air (OTA) upgrade procedures and vehicle owners (who must ensure that their software stays up to date).

Solutions and IP protection

One effective software solution that seeks to address the problem of securing automotive architectures is Symantec’s Critical System Protection. This helps to enforce the whitelisting of good code and reports anomalous behaviour in real-time, so that updates can be initiated when they’re needed.

Another is Continental’s In-Vehicle Network Protection and Monitoring, which identifies and blocks attacks by recognising anomalies within the vehicle network and sending alerts to its security operations centre.

The software focus of these innovations can make further innovations difficult to protect with patents. It’s key to remember that improvements to known technology can be patented — even if they’re software-related. We recommend always speaking to a patent attorney with specialist software experience to ensure that your innovation achieves the best protection possible.

If you need advice about protecting software innovation, get in touch with me for a free initial chat.

The logos of the Financial Times and Statista are shown, with the FT logo featuring black text on a cream background and the Statista logo in dark blue.
A hexagonal badge with the text "10+ YEARS IP STARS RANKED from Managing IP" in navy and gold on a cream background.
The logo features the words "The Legal 500" in stylised black and grey text with a modern, sleek design.
The IAM 300 logo features bold red and black text with a stylised red graphic element on a white background.
Text on a logo that reads "IAM 300 GLOBAL LEADERS 2025" with a design element of red three horizontal bars on the left.
The logo features stylised red lines, the text "IAM" in bold black and red, and "1000" underneath, set against a plain background.
WTR 1000 logo in various shades of blue, gold, and black, with a geometric design and text on a transparent background.
The image displays the Lexology Client and Industry News logo with a pattern of dark circles and the words "LEXOLOGY" and "INDUSTRY NEWS".
A round emblem with a gold eagle and the text "IP Eagle Talents 2024", surrounded by a gold border and a red ribbon with Chinese characters.
Logo of DéCIDEURS MAGAZINE featuring three shooting stars inside a circle and the magazine name in bold black and red text.
WIPR 2024 logo highlighting Diversity, with the tagline "Influential Woman in IP" on a teal background.
The Legal Benchmarking Social Impact Awards 2024 logo features a purple circle with "LBG" and bold black text to the right.
A colourful four-petal flower logo with a dark circle in the centre, accompanied by the text "IP INCLUSIVE" and the tagline "Working for diversity and inclusion in IP".
A colourful abstract logo with interconnected circles and the text "ADAPT.legal" underneath, set against a dark grey background.
European Patent Pipeline Program logo with the acronym "EPPP" in large pink letters above the full name in smaller dark blue text.
LSA logo with green text and leaf design, accompanied by black text reading "Legal Sustainability Alliance" and "Member | 2024".
A close-up of a cybersecurity badge featuring a blue background, green check mark, and the words "Cyber Essentials Certified."
A Cyber Essentials Plus logo featuring a blue and green circular emblem with a tick mark, accompanied by the text "CYBER ESSENTIALS PLUS".
The logo features the word "oveda" with a stylised, multicoloured swoosh design and the slogan “Invested in a better future” underneath.
Green and black logo featuring a stylised globe with wavy lines and the text "United Kingdom Best Managed Companies" beside it.