Turnkey-ready Development Platform and secure Gateway for Automotive Connectivity
With the Secure Automotive Connectivity Platform (SACoP), SYSGO has developed a fully integrated software framework for secure data exchange of connected vehicles. This includes vehicle-to-vehicle (V2V) and vehicle-to-infrastructure (V2X) as well as internal communication in the vehicle. The platform guarantees information Security by protecting data transfer through strict encapsulation and separation of all communication channels. This partitioning is complemented by a secure boot process, an integrated intrusion detection system and a firewall.
The platform uses SYSGO's PikeOS real-time operating system (RTOS) hypervisor technology, which allows critical and non-critical infrastructures to run simultaneously in one system. Through its resource and time partitioning, PikeOS meets all essential determinism and real-time requirements, providing the ability to build functionally safe systems. PikeOS can also safely and securely virtualize small programs up to entire operating systems separately. As a Type-1 hypervisor, PikeOS runs directly on the embedded hardware, making the overall system as powerful as possible. In addition, PikeOS supports certifiable multicore designs.
By combining real-time capability and hypervisor functionality in PikeOS to run applications in strictly separated partitions, Safety-critical applications in particular can be executed undisturbed within a specified time frame. The platform is pre-certified with the separation kernel version 4.2.3 (build S5577) according to the Common Criteria EAL3+ Safety standard and the ISO 26262 Safety standard for the automotive industry and is certifiable up to ASIL-D. This means that only one hardware system is required when planning the software architecture, which reduces development and production costs and accelerates time to market. The platform provides a flexible software framework to help customers design their software architecture to secure communication and updates.
The gateway, which supports various protocols (4G/5G), enables a wide range of applications, such as over-the-air updates without visiting an authorized garage, V2X communication, connectivity to the cloud backend or upload of maintenance data. Software and firmware components of the entire system are updated using secure communication via FIPS-certified Transport Layer Security (TLS). All update files are digitally signed to securely prevent manipulation.
Internally, a WLAN hotspot set up for passengers is protected by the platform's firewall. The vehicle's internal network (Ethernet, CAN) is separated and can only be accessed via secure and monitored channels. The gateway supports Virtual Local Area Networks (VLAN).