ISO 15031-7:2013
Road vehicles — Communication between vehicle and external equipment for emissions-related diagnostics — Part 7: Data link security
Road vehicles — Communication between vehicle and external equipment for emissions-related diagnostics — Part 7: Data link security
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 6
- Дата публикации:
- 22 июля 2013 г.
- Издание:
- ISO IS 15031 edition 2 version 1
- ICS:
- 13.040.50
ISO 15031-7:2013 gives guidelines for the protection of road vehicle modules from unauthorized intrusion through a vehicle diagnostic data link. These security measures offer vehicle manufacturers the flexibility to tailor their security to their own specific needs and do not exclude other, additional measures. ISO 15031-7:2013 applies to vehicle modules whose solid-state memory contents are able to be altered from outside the electronic module through a diagnostic data communication link. Such alteration could potentially damage a vehicle's electronics or other components, placing at risk its compliance with government legislation or the vehicle manufacturer's interests in respect of security.
Abstract
Overview
ISO 15031-7:2013 - Road vehicles - Communication between vehicle and external equipment for emissions-related diagnostics - Part 7: Data link security - provides guidelines to protect vehicle electronic modules (ECUs) from unauthorized intrusion via the vehicle diagnostic data link. The standard applies where solid‑state memory can be altered from outside the module through diagnostic communication - a risk that can affect emissions compliance, safety and manufacturer intellectual property. ISO 15031-7:2013 is based on SAE J2186 and gives manufacturers flexibility to tailor security measures without excluding additional protections.
Key Topics
- Scope and purpose: Protect modules whose memory contents are alterable via a diagnostic link to prevent tampering with emissions‑related functions.
- Security characteristics and implementation: Recommendations for access control mechanisms that separate unsecured functions (e.g., clearing fault codes) from secured functions (e.g., programming emission maps, odometer).
- Challenge–response model: Concepts of seed (pseudorandom value supplied by the ECU) and key (response value sent by external equipment) to unlock secured functions.
- Failure management: Definitions and handling for false access attempts (FAA) and use of delay time (DT) between access attempts to mitigate brute‑force attacks.
- OSI mapping and supported data links: Integration with the OSI model and diagnostic protocols used for emissions diagnostics - DoCAN (ISO 15765‑4), SAE J1850, ISO 9141‑2, and DoK‑Line (ISO 14230‑4).
- Normative references: Cross‑references to related diagnostic and network standards that define transport, session and physical layers and diagnostic services.
Applications
Who uses ISO 15031-7:2013 and why:
- Vehicle manufacturers (OEMs): to define and implement ECU access control and protect emissions‑related firmware and calibration data.
- ECU and module suppliers: to design secure diagnostic interfaces and incorporate seed/key or equivalent mechanisms.
- Diagnostic tool vendors: to ensure external test equipment interacts correctly with secured/unsecured functions and complies with emissions testing regimes.
- Regulators and test labs: to assess if diagnostic interfaces preserve emissions compliance and resist unauthorized modification.
- Automotive cybersecurity teams: to include data link security in threat models and mitigation strategies for connected vehicles.
Practical benefits include preventing unauthorized reprogramming that could defeat emissions controls, preserving legal compliance, and protecting vehicle safety and brand integrity.
Related Standards
Key related documents referenced by ISO 15031-7:2013:
- ISO 15031-1, -2, -5, -6 (series on emissions-related diagnostics)
- ISO 15765-2 / ISO 15765-4 (DoCAN transport/network and emissions requirements)
- ISO 11898-1 / ISO 11898-2 (CAN)
- ISO 14229-2 (UDS session layer)
- ISO 14230-2 / ISO 14230-4 (DoK‑Line / K‑Line)
- ISO 9141-2, ISO/IEC 7498-1 (OSI model), SAE J1979-DA, SAE J1930-DA
Keywords: ISO 15031-7:2013, data link security, vehicle diagnostic data link, OBD security, ECU protection, seed/key, emissions-related diagnostics, DoCAN, diagnostic communication.
Технические детали
- Технический комитет
- ISO/TC 22/SC 31 - Data communication
- SKU
- ISO 15031-7:2013
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO 15765-4:2021
ДействующийRoad vehicles. Diagnostic communication over Controller Area Network (DoCAN). Requirements for emissions-rela…
ISO 9141-2:1994
ДействующийRoad vehicles — Diagnostic systems — Part 2: CARB requirements for interchange of digital information
Overview ISO 9141-2:1994 - "Road vehicles - Diagnostic systems - Part 2: CARB requirements for interchange of digital information" defines a CARB-focused subset of ISO 9141 for on‑board diagnostic co…
ISO 14230-4:2000
ДействующийRoad vehicles — Diagnostic systems — Keyword Protocol 2000 — Part 4: Requirements for emission-related systems
Overview ISO 14230-4:2000 specifies the requirements for the Keyword Protocol 2000 (KWP2000) data link and connected vehicle and scan tool when used to comply with on-board diagnostic (OBD) requireme…