Be first to read the latest tech news, Industry Leader's Insights, and CIO interviews of medium and large enterprises exclusively from Medical Tech Outlook
THANK YOU FOR SUBSCRIBING
A featured contribution from Leadership Perspectives: a curated forum reserved for leaders nominated by our subscribers and vetted by our MedTech Outlook APAC Advisory Board.

Yueqiang Cheng, Director, Head of Software Security & Tools


Dr. Cheng is the Director, Head of Software Security & Tools at NIO's Advanced Research and Innovation Center in Silicon Valley, California, United States. He leads a product security team focused on highly innovative security research initiatives and architecture designs to further ensure NIO's security.
Before joining NIO, Dr. Cheng was a Senior Staff Security Scientist at Baidu Research and worked on system security, software security, and microarchitecture security. He was also a Postdoctoral Fellow at CMU CyLab with Professor Virgil Gligor.
He has published several high-quality papers at top-tier academic conferences and journals, including ASPLOS, CCS, Usenix Security, NDSS, MICRO, ICSE, IEEE TDSC, IEEE TIFS), as well as industry conferences (e.g., BlackHat, Defcon, Bluehat, CanSecWest).
With this vast industry expertise, Dr. Cheng has noticed, unsurprisingly, that connected vehicles are becoming increasingly attractive targets for cyber attackers due to the large amount of valuable data that can be accessed and the potential safety risks posed by compromising vehicle systems. Therefore, to address vehicle security threats, it is necessary to conduct comprehensive vulnerability and risk assessments, develop targeted security protection strategies, and deploy appropriate security solutions. This may involve a range of measures, including secure software development practices, network encryption, access control and authentication mechanisms, intrusion detection and prevention systems, and regular security audits and assessments.
Only vehicles holding R155 CSMS and VTA model certifications are authorized for sale in the European Union. These certifications, along with the ISO/SAE 21434 CSMS certification obtained by NIO, ensure that the security of our products is maintained throughout their entire lifecycle. This includes the conception, design, development, testing, production, and post-production stages, providing comprehensive security coverage and enhancing research and development efficiency. NIO is committed to delivering vehicles that meet the highest safety and security standards.
"As the popularity of electric vehicles continues to rise, the need for a comprehensive cybersecurity protection mechanism has become increasingly crucial in safeguarding user safety. To address vehicle security threats, comprehensive vulnerability, and risk assessments are necessary, develop targeted security protection strategies, and deploy appropriate security solutions."
NIO's robust research and development capabilities and advanced electric vehicle systems have been designed with elevated security levels to safeguard users and associated products from cyber security risks. In addition, prompt and efficient responses are provided during cyber security threats or attacks, ensuring that users' assets and personal security are protected.
Compliance with the R155 regulation is largely supported by the ISO 21434 standard, which defines the complete framework for vehicle cybersecurity and related cybersecurity life cycle processes. As of July 2022, all newly marketed vehicle types in UN countries must possess R155 CSMS and R155 VTA certifications. The R155 VTA certification requires specific work item reviews for cyber security development to ensure the successful implementation of cyber security protection technologies and vehicle mechanisms.
Acquiring R156 SUMS certification guarantees alignment between the vehicle design and software update processes. In addition, the Software Update Management System (SUMS) ensures the security of vehicle software updates, eliminating security threats throughout the software update process and ensuring the security of both the process and the software itself.
NIO has developed a comprehensive range of security technology and research and development capabilities, encompassing the complete life cycle of automotive software and hardware development, vehicle production and operation, and maintenance. These capabilities include threat analysis, risk management, incident response, vulnerability management, vehicle security monitoring, supplier cybersecurity management, production line cybersecurity, vehicle after-sales security updates, and end-of-life management. This extensive set of capabilities ensures the continuous security and safety of NIO vehicles throughout their life cycle.
Moreover, NIO has implemented a comprehensive security defense system that covers cloud, channel, and endpoint security. This system comprises independently developed PKI (Public Key Infrastructure) systems, security diagnostic tools, data security systems, vehicle intrusion detection and defense systems, and other security products. Cloud security is maintained through strict access control policies, cloud firewalls, failover mechanisms, and off-site disaster recovery. The vehicle's onboard system is secured using VLAN networks, OBD firewalls, security OTA, access control, and data security protection. The mobile phone endpoint is secured through equipment certificates, APP reinforcement, PIN code verification, and login defense systems. Finally, communication channel security is ensured through APN network access, channel encryption, and other security measures.
NIO has proactively addressed these challenges by developing several security systems, including a data security system, a secure cloud service center, a vehicle IDS/IPS system, and security diagnostic tools. The data security system ensures the protection of sensitive data through desensitization processing, secure transmission, protected and trusted computation/analysis, encryption storage, and the full lifecycle management. The secure cloud service center employs Public Key Infrastructure (PKI) technology and digital certificates to provide system information security services and verify the identity of digital certificate holders. Meanwhile, the onboard IDS/IPS system provides comprehensive monitoring and defense against cyber-attacks, and dedicated security diagnostic tools are used to diagnose vehicles.
As the popularity of electric vehicles continues to rise, the need for a comprehensive cybersecurity protection mechanism has become increasingly crucial in safeguarding user safety.
I agree We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info
