NEWS & REPORTS

Cybersecurity Best Practices for Aftermarket Electronics and Telematics in Heavy Vehicles

Jul 28, 2020 | Reports

Read the entire report here.

Goal:

To develop a set of best practices and guidelines focused on minimizing cyber risks for aftermarket electronic systems intended for use in the commercial motor vehicle (CMV) industry.

Background:

Heavy vehicle fleet operators routinely integrate a variety of aftermarket electronic systems into the trucks and buses they operate. Such systems include telematics units, navigation, infotainment, vehicle diagnostics, cargo monitoring and vehicle anti-theft systems, as well as a variety of driver monitoring, crash avoidance and other systems that may aid in compliance or operation of the vehicle. Often, these devices and systems are integrated into the vehicle’s electrical architecture including potential linkages with the vehicle’s CAN databus, driver display systems, or other electronic sub-systems on the vehicle.  Further, the aftermarket/telematic devices themselves will often incorporate a wireless or wired connection, (or perhaps a manual input interface) that allows for connecting the device to its intended interface entity. Such interfaces, with their integration into the vehicle’s electronic systems, offer a potential cyber vulnerability or a “point of entry” that may allow “bad actors” to gain access first to the aftermarket system, and then subsequently to the vehicle’s control sub-systems, including driver interface, braking, throttle and or steering systems. Such connections may possibly be “hacked” to allow malicious attacks such as retrieving propriety data stored on the vehicle, or creating congestion on the vehicle networks such that normal and safe operation of the vehicle is compromised.  As telematic and related aftermarket electronic devices and systems continue to proliferate the heavy vehicle marketplace, such cyber threats are of a growing concern to the Federal Motor Carrier Safety Administration (FMCSA), the National Highway Traffic Safety Administration (NHTSA) and the heavy vehicle industry.

Summary:

For this joint project with NHTSA, the contractor will build on existing heavy vehicle cybersecurity research to more narrowly focus on cyber threats and vulnerabilities associated with the integration and use of a variety of aftermarket and telematic systems intended for heavy vehicle application. The output of this research will be a set of best practices and guidelines for both the design and integration of aftermarket electronic systems focused on minimizing cyber risks. To this extent, the output of this work may be used by both the suppliers of such systems as well as by end users.

About the Author

NEWS & REPORTS

FMCSA unveils ‘more fair and transparent’ DataQ system

Mark Schremmer The Federal Motor Carrier Safety Administration announced this week that it is taking steps to address those problems. DataQ is an electronic system run by the FMCSA that allows motor carriers, drivers and safety officials to request a review of data in...

FMCSA overhauling DataQ system

How this affects you: More success on legitimate challenges: Fleets will no longer face "rubber-stamp" denials from the same officer who issued a citation; the new rule mandates independent, multi-stage reviews to eliminate conflicts of interest. Strict timelines for...

FMCSA moving forward with crash risk study

Mark Schremmer The Federal Motor Carrier Safety Administration is moving forward with a study looking at how a truck driver’s work schedule relates to crash risk. In a notice that was published in the Federal Register on Monday, April 20, FMCSA said the study, “Crash...

ELD tampering in crosshairs for CVSA’s annual Roadcheck blitz

Overdrive Staff   It didn’t take long for the Commercial Vehicle Safety Alliance to highlight one of its newest out-of-service violations. Earlier this week, the alliance of state/federal enforcement and industry announced false-log violations as a result of ELD...

CVSA’s International Roadcheck Scheduled for May 12-14

Washington, D.C. (Feb. 12, 2026) – From May 12 to 14, enforcement personnel throughout North America will inspect commercial motor vehicles and commercial motor vehicle drivers for compliance with vehicle, cargo and driver regulatory requirements as part of the...

CATEGORIES