Showing posts with label Highly Automated Vehicles. Show all posts
Showing posts with label Highly Automated Vehicles. Show all posts

Thursday, October 5, 2017

Senate Committee Amends/Approves S 1885 – Automated Vehicles

Yesterday the Senate Commerce, Science, and Transportation Committee adopted 26 amendments to S 1885, the AV START Act and then passed the bill on a voice vote. Only 7 of the 26 amendments dealt with cybersecurity measures in the bill.

Minor Changes


Most of the cybersecurity related amendments made minor changes or additions to the current language of the bill. These included:

Hassan 4 – Added supply chain concerns to definition of ‘cybersecurity’ and to the requirements for the cybersecurity plan in §14;
Klobuchar 2 – Added informing driver of cyber vulnerabilities to definition of ‘cybersecurity’;
Schatz 2 – Added requirement for manufacturers to make a summary of the cybersecurity plan available to public;
Gardner 2 – Added requirement for manufacturers to provide employee training on their cybersecurity plan;
Klobuchar 1 – Added requirement for the Technical Committee to review vehicle communications with ‘roadway and infrastructure assets’.

Major Additions


The two remaining amendments added new sections to the bill.

Wicker 2 addressed consumer cybersecurity education in two new sections. First it added requirements for DOT to “develop educational cybersecurity resources to assist consumers in maintaining awareness of and minimizing potential motor vehicle cybersecurity risks” {new §15(a)(1)}. Those resources would be made available on the National Highway Traffic Safety Administration (NHTSA) web site. It would then require manufacturers to direct consumers to those resources.

Inhofe 2 provided requirements for the establishment of an HAV [Highly Automated Vehicle] Data Access Advisory Committee. This Committee would be tasked with making policy recommendations to Congress about “the ownership of, the control of, or access to information or data that vehicles collect generate, record or store” {new §15(d)(1)}. It also prohibits the Federal Government from making any rules on the regulation of such data until the Committee makes its recommendations.

In making its recommendations that Committee will consider the following factors {new §15(d)(4)(B)}:

• Motor vehicle safety;
• Intellectual property protections;
• Compliance with the Motor Vehicle Safety Act;
• Customer privacy;
• Cybersecurity;
• Confidential business information;
• Public safety; and
• Transportation planning.

 Moving Forward


The voice vote approval of this bill in Committee is indicative of the expected broad bipartisan support for this bill. If this bill makes it to the floor of the Senate, I would expect that support to continue.

Commentary


My concerns about the conflicting and inadequate cybersecurity related definitions included in this bill were not addressed. In fact, the changes to the specific definition of ‘cybersecurity’ {new §30107(b)(4)} made by Hassan 4 and Klobuchar 2 described above only make things more confusing. The revised definition reads:

CYBERSECURITY. The minimization of cybersecurity risks to safety including evaluation of elements of the supply chain to identify and address cybersecurity vulnerabilities and the exchange of information about any vulnerabilities discovered from field incidents, internal testing, or external security research and mechanisms for alerting the human driver or operator about cyber vulnerabilities.


The use of this definition is limited to the requirements for the safety evaluation report to be prepared by vehicle manufacturers introducing new HAV’s, but it still reflects congressional technology confusion and a tendency to glop together fad terminology rather than understand complex concepts.

Wednesday, August 23, 2017

HR 3411 Introduced – Automated Vehicle Advisory Council

Last month, as part of a series of bills on highly automated vehicles that were introduced on the same day as HR 3388 was revised by the House Energy and Commerce Committee, Rep. Costello (R,PA) introduced HR 3411. This bill would require DOT to establish the Automated Driving System Cybersecurity Advisory Council. An identical provision was included as §9 in HR 3388.

The Council


The Council would be established under the provisions of the Federal Advisory Committee Act (5 USC Appendix). It would consist of 15 to 30 members representing “business, academia and independent researchers, State and local authorities, safety and consumer advocates, engineers, labor organizations, environmental experts, a representative of the Na1tional Highway Traffic Safety Administration, and other members determined to be appropriate by the Secretary” {§1(b)}.

The Council would advise the DOT Secretary on “cybersecurity for the testing, deployment, and updating of automated driving systems with respect to supply chain risk management, interactions with Information Sharing and Analysis Centers and Information Sharing and Analysis Organizations, and a framework for identifying and implementing recalls of motor vehicles or motor vehicle equipment” {§1(e)}.

Moving Forward


As with the other two bills that I have discussed in this series (HR 3401 and HR 3407), it looks like this bill was introduced so that key components of HR 3388 could still be passed by the House if the Republican leadership determined that some of the more controversial (and non-cybersecurity related) provisions of the bill would prohibit consideration of HR 3388. If the leadership decides not to move forward with HR 3388 I expect most of this series of bills would be considered in a single day under the suspension of the rules provision. That would allow for limited debate and no floor amendments. I suspect that the three cybersecurity related bills would pass with a substantial bipartisan majority.

Commentary


The DOT has a long history of using these advisory committees to produce consensus rulemakings on deeply technical topics. The involvement of industry representatives and various activist organizations helps to ensure that a multitude of voices are heard in the development process.

Having said that, I am disappointed that two groups were not specifically identified in the list of entities to be included. I would have liked to see Automotive ISAC specifically listed as a central industry group that should be represented. On the government side, I would have liked to have seen the DHS ICS-CERT specifically mentioned as an agency (along with the current mention of NHTSA) that would have a representative on the Council. I think that these two would be important additions to provide specific cybersecurity expertise for these the complex control systems associated with highly automated vehicles.


The Secretary still has a great deal of leeway to add representatives of these two organizations to the Council, but a Congressional mandate for at least the ICS-CERT would have made the inter-departmental appointment much easier.

Tuesday, August 22, 2017

HR 3407 Introduced – Automated Vehicles Cybersecurity

Last month Rep. Kinzinger (R,IL) introduced HR 3407, which would add a requirement to 49 USC for manufacturers of highly automated vehicles to provide a cybersecurity plan for those vehicles. This is part of a series of bills that were introduced by members of the House Energy and Commerce Committee that could serve as alternatives to the passage of the amended HR 3388 that was adopted by the Committee on July 27th.

This bill would provide the same new §30130, Cybersecurity of automated driving systems, found in the revised HR 3388. I discussed this section in detail in my earlier blog post on HR 3388.

Commentary


I have heard it suggested that this series of bills may have actually preceded the amendment of HR 3388, rather than, as I explained in my post on HR 3401, serving as an alternative to passing the more complex bill to ensure that key provisions make it into law. There are two different items in this bill that support my contention. First, the definitions found in this bill {§2(b)} are identical to those provided both in HR 3388 {§13(a)} and HR 3401 {§1(b)}. This shows significant staff coordination during the crafting of these three bills.

Second §1(a) of this bill is identical to §5(a) of HR 3388. They both introduce the proposed §30130, saying:

“IN GENERAL.—Chapter 301 of subtitle VI of title 49, United States Code, is amended by inserting after section 30129 (as added by section 4) [emphasis added] the following new section:”


There is no section 4 in this bill; there is no §30129 mentioned in this bill. What this clearly means is that §1(a) of this bill was lifted en toto from the revised HR 3388. The staff did not do a really good job of cutting (editing) and pasting when they prepared this bill. It does provide clear insight, however, into the order of crafting HR 3388 and the subsequent series of bills introduced on the same topic.

Tuesday, August 15, 2017

HR 3401 Introduced – Automated vehicles

Last month Rep. Schakowsky (D,IL) introduced HR 3401, a bill that would require the DOT’s National Highway Transportation Safety Administration (NHTSA) to establish new automotive safety standards for highly automated vehicles. This bill was introduced the same day that the House Energy and Commerce Committee  amended HR 3388 to do the same thing.

This bill is nearly identical to Section 4 of the revised HR 3388 adopted by the Committee. There is one area where the paragraph numbering is slightly different, but there are no substantive differences between the requirements. It would amend 49 USC by adding a new §30129, Updated or new motor vehicle safety standards for highly automated vehicles.

It would require DOT to “issue a final rule requiring the submission of safety assessment certifications regarding how safety is being addressed by each entity developing a highly automated vehicle or an automated driving system” {new §30129(a)(1)}.

It would also require DOT to submit to Congress a regulatory and safety priority plan designed to accommodate the development and deployment of highly automated vehicles while ensuring “the safety and security of highly automated vehicles and motor vehicles and others that will share the roads with highly automated vehicles” {new §30129(c)(1)}. That plan would include a requirement for NHTSA to “identify elements that may require performance standards including human machine interface and sensors and actuators, and consider process and procedure standards for software and cybersecurity as necessary” {new §30129(c)(2)(B)}.

Moving Forward


Ms. Schakowsky is the ranking member of the Digital Commerce and Consumer Protection Subcommittee of the House Energy and Commerce Committee. Normally this would probably allow her to have this bill considered in Committee. In this case, however, because this bill was introduced the same day that HR 3388 was, it seems as is the bill was introduced as a backup measure to ensure that the safety standards provisions of this bill could end up being considered separately from the remainder of the provisions of the larger bill if that bill was determined to be too controversial to be considered on the floor of the House.

I suspect that this bill will not see any further action until the House Leadership determines whether or not HR 3388 will make it to the floor. If it does not, this bill will likely be moved to the floor for a vote without going through a separate review by the Committee.

Commentary


I did not mention the cybersecurity requirements described above in my discussion of HR 3388 because they were duplicative of the requirements that I described but were not as expansive as the cybersecurity requirements in §5 of HR 3388.


What is important (and unusual from a cybersecurity perspective) here is that both bills would require the establishment for safety standards for HMI, sensors and actuators. It does not include any guidance on what those standards would include, but that would normally be expected to be developed by the technical experts at NHTSA. But this would end up being where the Federal government took its first crack at developing safety (and perhaps specific cybersecurity) standards for key components found in (almost by definition) these critical components of control systems. Those standards could end up being ground breaking regulatory standards for the ICS industry.
 
/* Use this with templates/template-twocol.html */