China is taking a significant step towards bolstering the cybersecurity of its rapidly growing intelligent connected vehicle (ICV) market. The Ministry of Industry and Information Technology (MIIT) has released a draft of a mandatory national standard, “Technical Requirements for Automotive Password Applications,” for public comment. This initiative aims to address the escalating security challenges posed by increasingly complex vehicle software and connectivity.
Addressing Evolving Threats
The rapid proliferation of advanced driver-assistance systems (ADAS) and the commercial pilot of Level 3 autonomous driving have led to a surge in the complexity of vehicle software, with codebases now exceeding one billion lines. Coupled with extensive vehicle-to-everything (V2X) communication across various scenarios (V2V, V2I, V2N), the entire lifecycle of data – from collection and transmission to storage and processing – faces unprecedented security threats. Recent cyberattacks on ICVs, including remote control, data theft, and system tampering, highlight that these risks have moved from theoretical concerns to tangible realities, potentially impacting personal safety, public security, and even national security.
The Role of Cryptography
Cryptography is identified as the cornerstone technology for establishing a robust, inherent defense system in vehicles. It enables critical security functions such as identity authentication, data encryption, integrity protection, and non-repudiation. The goal is to create a vehicle ecosystem that is resistant to unauthorized access, data exfiltration, eavesdropping, modification, and escape from control – encapsulated by the phrase “cannot enter, cannot take, cannot understand, cannot modify, cannot escape.”
Identifying Key Challenges
Despite the recognized importance of cryptography, the current application within the automotive sector suffers from a lack of top-level design, fragmented technical requirements, and missing implementation standards. The proposed standard seeks to fill this void and resolve three prominent contradictions in current automotive password applications:
- Algorithm and Module Standardization: A lack of unified, mandatory technical requirements for the selection of cryptographic algorithms and modules leads to the use of non-standard or non-compliant modules, creating security vulnerabilities.
- Incomplete Application Scenarios: The depth and breadth of cryptographic technology application are inconsistent across crucial stages, from secure boot to vehicle-cloud communication and remote control, indicating a lack of systematic standards.
- Weak Management and Lifecycle Security: The capabilities for cryptographic management and full lifecycle key security assurance are weak, with security blind spots existing in key generation, storage, distribution, usage, and destruction.
Key Provisions of the Draft Standard
The draft standard introduces several critical requirements for vehicle manufacturers:
- Algorithm Verification: Manufacturers will be prohibited from using self-developed or proprietary algorithms that have not undergone standardized verification or official approval. Appropriate parameters and options must be selected based on different algorithms and business scenarios.
- Secure Software Loading: Vehicles must employ cryptographic technologies to ensure that software components loaded during power-on or reboot are genuine, complete, and trustworthy. This is crucial to prevent the execution of firmware, bootloaders, operating systems, or critical applications that have been illegally tampered with, replaced, or forged.
- Hierarchical Trust Chain: Vehicle manufacturers must establish a tiered trust chain for critical systems, extending from the bottom-level firmware to the upper-level applications. This involves layered security verification of key components during the boot process, supported by mechanisms like trusted roots, key/certificate management, signature verification, and integrity checks to ensure the trustworthiness of the verification basis itself.
- Integration with Business Scenarios: The secure boot mechanism needs to be integrated with other business scenarios, such as remote control, Over-The-Air (OTA) updates, autonomous driving data recording, and other critical systems identified through risk assessment. In case of verification failure, measures such as blocking loading, entering a safe state, issuing alarms, or reverting to a trusted version must be implemented to prevent the vehicle from operating in an untrusted software environment.
- Update Package Integrity: Both online and offline software updates, including those downloaded from public terminals without secure channels, must undergo verification of authenticity and integrity using cryptographic techniques like digital signatures or Message Authentication Codes (MACs) before execution. Measures like prohibiting plaintext export will be employed to prevent key leakage.
- Third-Party Application Security: During the authorization, access, invocation, and data interaction of third-party applications, manufacturers must use cryptographic mechanisms such as digital signatures (based on public-key cryptography) or MACs (based on symmetric cryptography) to verify the genuine identity of third-party applications and the integrity of the interacted data. This verification should cover application interface calls, critical business commands, and data transmission content, and be integrated with key management, permission control, access control, and exception handling to ensure that only authorized and untampered third-party applications can access vehicle resources.
This proposed standard represents a proactive and comprehensive approach by China to enhance the security posture of its automotive industry, laying a foundation for safer and more trustworthy intelligent connected vehicles.









