唯一一款获得 ISO 26262 认证(通过 UL)的无线软件更新产品,具有 ASIL-D 评级,可安全放心地将软件和固件更新部署到任何 ECU。
可自定义的 “安全状态” 检查,确保道路车辆在执行任何可能导致人身安全隐患的 ECU 软件更新之前和之后处于安全状态(未行驶)。
Sibros 的系统确保只能安装 OEM 签名的软件或固件的有效版本,以降低参数设置不正确或恶意软件入侵的风险。
持续监控 ECU,确保它们经过全面正确编程,按预期运行。
在客户发布之前,我们通过广泛的概念测试和分析,确保所有新产品和概念的功能安全。
作为首批也是唯一一家获得 ISO 21434 认证的联网汽车平台提供商之一,Sibros 在整合强大的网络安全实践方面处于领先地位,以确保最高水平的安全、安保和客户信任。
Sibros 精心开发了一个应用程序安全框架,该框架在设计上是安全的,符合 ISO 27034 中概述的严格安全协议。
网络安全管理系统 (CSMS) 和软件更新管理系统 (SUMS) 的技术特性和机制可帮助 OEM 实现 R155、R156 和 R169 监管合规性。
网络安全管理系统 (CSMS) 和软件更新管理系统 (SUMS) 的技术功能和机制可帮助印度原始设备制造商达到 AIS-189 和 AIS-190 监管合规性。
我们的系统采用抗折衷的 Uptane 框架,旨在为地面车辆的空中软件更新提供多层网络安全和威胁防护,使其免受不良行为者的攻击。
使用 HTTPS/MQTTS 确保车辆与云端之间安全可靠的数据交换。
对命令和更新进行批准和身份验证,要求在多个接入点和用户之间使用签名密钥,以防止篡改和未经授权的使用。
所有软件版本、更新包、系统变更和相关载具都使用唯一标识符来实现一致性、透明度、验证和可追溯性。
Sibros 的多层身份验证和安全方法可防范多种恶意活动,例如窃听、丢弃请求、慢速检索、冻结攻击、回滚攻击等。
美国注册会计师协会 (AICPA) 系统与组织控制 (SOC) 对内部控制和我们保护客户数据的有效性进行了认证。
通过质量管理体系 (QMS) 和框架认证,可持续改进我们向您提供的产品和服务。
我们的专门风险委员会根据我们的事件响应政策中概述的指导方针监督潜在威胁的检测、评估和记录。
需要在整个组织内就所有新的操作程序、强制性合规主题和相关最佳实践进行持续的沟通和培训。
所有员工都经过全面的审查流程,包括多次面试、犯罪背景调查和入门培训。员工离职后,立即禁用对公司系统、服务和应用程序的访问。
Sibros follows an approach of security designed from the ground up and built into the DNA of the product. This includes in-vehicle secure communications and secure storage / HSM integrations.
All access needs authorization and is granted on a need-to-know basis. All employees are background checked as part of their onboarding process.
Our solution is assessed to TISAX, SSAE 16/18 SOC 2 Type 2, ISO 26262 (ASIL-D) in place with ISO 27001, ISO 21434, and ISO 24089 in progress. Sibros also addresses and supports security regulations such as UNECE WP.29 R155 and R156, with AIS 189, AIS 190 under review; as well as privacy regulations such as GDPR and CCPA, with Indian DPDP under review.
Support for 0x27 and key exchange, secure storage and symmetric key handling to be determined by target ECU.
Sibros Armor includes the following checks and failsafes:
Sibros has a very well defined incident management process, and security incident management and breach response processes.
All changes for cloud and firmware are reviewed.
Sibros acts as a data processor. The OEM is the data controller.
The following are used:
Sibros primarily uses a Globally Unique Identifier (GUID) to create a link between device identification information such as Vehicle Identification Number (VIN) / Electronic Serial Number (ESN) and the data collected by Deep Logger, Deep Updater, and Deep Commander.
With the following reviews and assessments:
Security is designed into the solution. Additionally, it is assessed to TISAX, SSAE 16/18 SOC 2 Type 2, ISO 26262 in place with ISO 27001, ISO 21434, and ISO 24089 in progress.
Log files are archived and optionally compressed. They are also handled securely and not directly uploaded into the system. The only reference information is in the system, and the S3 bucket is only used for storage of files that are uploaded as GUID’s (Globally Unique Identifiers).
The following measures are taken:
Uptane is the first security framework for automotive OTA updates that provides serious compromise resilience, meaning that it can withstand attacks on servers, networks, keys, or devices. The differences are as follows:
The following are used: