A Resilient And Integrity-Verified Over-The-Air Software Update Architecture For Software-Defined Vehicles

Authors

  • Srikanth Puram

Keywords:

Over-the-Air Updates, Software-Defined Vehicles, Cybersecurity, Firmware Integrity, Fault Tolerance, Automotive Software, Cryptographic Verification, UNECE WP.29.

Abstract

Software-Defined Vehicles (SDVs) increasingly rely on over-the-air (OTA) update mechanisms to deliver enhanced functionality, security patches, and performance improvements across their lifecycle. However, existing OTA architectures expose vehicular systems to significant risks, including firmware tampering, incomplete update rollouts, replay attacks, and man-in-the-middle exploits. This paper proposes a resilient and integrity-verified OTA update architecture specifically tailored for SDV deployment. The proposed framework integrates a four-layer security stack comprising a secure authentication layer, a cryptographic integrity verification layer, a fault-tolerant resilient delivery layer, and a vehicle update manager responsible for controlled deployment and rollback. Formal threat modeling using STRIDE and TARA methodologies underpins the security design, while A/B partition-based rollback ensures operational continuity during update failures. Comparative analysis against existing OTA paradigms demonstrates that the proposed framework substantially improves update reliability, reduces mean-time-to-recovery (MTTR), and strengthens resistance to adversarial exploits. The architecture is aligned with UNECE WP.29 R156 regulations and ISO/SAE 21434 cybersecurity standards, making it suitable for production deployment in modern connected automotive ecosystems.

Downloads

Published

2026-06-14

How to Cite

Puram, S. (2026). A Resilient And Integrity-Verified Over-The-Air Software Update Architecture For Software-Defined Vehicles. International Journal of Artificial Intelligence and Machine Learning, 6(5s), 929–936. Retrieved from https://www.svedbergopen.com/index.php/ijaiml/article/view/655