Overview
ISO/TR 23791:2019 is a technical report that documents the risk assessment of the ISO 20078 series - the web‑service interface specification for the Extended Vehicle (ExVe) concept. The report evaluates potential safety, security, competition, liability (responsibility) and data protection risks that could originate from the ISO 20078 interface itself. Importantly, the document clarifies that risks arising from implementations, operational communication processes, resource‑owner authorization workflows, and risk‑mitigation measures are outside its scope. The Introduction concludes that the ISO 20078 series does not inherently create risks, though implementations might.
Key topics and technical focus
ISO/TR 23791 organizes the assessment into structured categories and annexes and addresses specific technical concerns such as:
- Safety risks (Annex A): overload scenarios of vehicle electronic systems (e.g., numerous, frequent or unexpected requests), illicit remote control, compatibility with existing systems, communication failures, lifecycle and design‑validation gaps, and lack of misuse prevention.
- Security risks (Annex B): integrity and authenticity of data, cybersecurity at systems beyond the moving vehicle, consequences of partial/full security breaches (impacting safety, confidentiality and competition), and OAuth2‑related considerations for authorization.
- Competition risks (Annex C): misuse of acquired data, market monitoring giving unfair advantage, profiling of customer behaviour, exclusion of competitors from roles or markets, and implications for after‑sales application development and supplier/ OEM competition.
- Liability and responsibility (Annex D): allocation of responsibility among ExVe actors (offering parties, resource owners, authorization providers, intermediate bodies, etc.).
- Data protection risks (Annex E): protection of resources owned by the resource owner (personal or vehicle data) and related privacy concerns.
The report also maps relevant terms and actor definitions (accessing party, offering party, resource owner, identity provider, etc.) used by ISO 20078.
Practical applications - who uses this standard
ISO/TR 23791 is a guidance and risk‑assessment resource for organizations working with vehicle web services and ExVe architectures, including:
- Vehicle and ExVe manufacturers (OEMs) - to inform API and backend design choices and to commission secure implementations.
- Telematics and software suppliers - for threat modeling and specification alignment with ISO 20078.
- Cybersecurity and privacy teams / DPOs - to guide vulnerability assessments and privacy impact assessments.
- Regulators, procurement and legal teams - to evaluate competition, liability and compliance implications.
- Third‑party service providers and identity/authorization providers - to understand actor roles and risk vectors when integrating with ExVe APIs.
Related standards
- ISO 20078 series - the web‑service interface specification assessed by this report.
- ISO/TR 23786 - criteria used as a baseline for independent risk assessment.
- OAuth2 and related authentication/authorization frameworks are specifically discussed with regard to security considerations.
Keywords: ISO TR 23791, ISO 20078, Extended Vehicle, ExVe web services, risk assessment, vehicle web services, safety risks, security risks, data protection, competition risks, OAuth2.