Showing posts with label V2V. Show all posts
Showing posts with label V2V. Show all posts

Thursday, January 19, 2017

NHTSA Publishes V2V Communications NPRM

Last week the DOT’s National Highway Transportation Safety Administration (NHTSA) published a notice of proposed rulemaking (NPRM) in the Federal Register (82 FR 3854-4019) to establish a new Federal Motor Vehicle Safety Standard (FMVSS), No. 150, to mandate vehicle-to-vehicle (V2V) communications for new light vehicles and to standardize the message and format of V2V transmissions.

The new FMVSS would establish a requirement for all new light vehicles (< 10,000 lbs gross vehicle weight) would include include vehicle-to-vehicle communication technology able to transmit standardized Basic Safety Messages (BSMs) over dedicated short-range radio communication (DSRC) devices. The requirement would be phased in over a three year period starting two years after the issuance of the final rule.

The lengthy NPRM (434 pages) breaks the NTSA proposal into seven sections:

• The actual communications technology itself;
• Proposed messaging format and content requirements;
Authenticating V2V messages;
Malfunction indication requirements;
Software and certificate updating requirements; and
• Proposed cybersecurity related requirements.

The discussion of cybersecurity requirements is rather extensive in the preamble to the proposed rule. The actual specific cybersecurity requirements in the proposed FMVSS, however, are currently space holding messages where the cybersecurity requirements will be listed (see for example here). This is because NHTSA still has a lot of questions for which it is seeking responses on cybersecurity issues. NHTSA is addressing the cybersecurity concerns with the following general comment (and then a number of questions about specific issues):

“NHTSA seeks comments regarding the cybersecurity needs and requirements and how regulatory language could be crafted to appropriately express the requirements in terms that industry can implement and in terms by which performance can be objectively evaluated.”


NHTSA is seeking public comments on this NPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2016-0126). Comments need to be submitted by April 12th, 2017.

Friday, May 20, 2016

Spring 2016 Unified Agenda – DOT

As I mentioned yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) published the Spring 2016 Unified Agenda. Today I want to look at the Unified Agenda for the Department of Transportation. I do not follow this portion of the Unified Agenda as closely as I do the DHS portion; mainly because DOT is a much more prolific writer of regulations than is DHS.

The Current Agenda


The table below lists the DOT rulemakings on the current agenda that I find interesting. This is a smaller set of interest than I normally follow here in this blog, but I do have some space and reader interest limitations that I need to take into consideration.

FAA
Proposed Rule Stage
Operations of Small Unmanned Aircraft Over People
FAA
Final Rule Stage
Operation and Certification of Small Unmanned Aircraft Systems
FAA
Final Rule Stage
Registration and Marking Requirements for Small Unmanned Aircraft
NHTSA
Proposed Rule Stage
Federal Motor Vehicle Safety Standard FMVSS 150 -- Vehicle to Vehicle (V2V) Communication
PHMSA
Proposed Rule Stage
Hazardous Materials: Review and Update of Rail Carrier Regulations in Part 174 RRR
PHMSA
Proposed Rule Stage
Hazardous Materials: Oil Spill Response Plans and Information Sharing for High-Hazard Flammable Trains
PHMSA
Proposed Rule Stage
Hazardous Materials: Real-Time Emergency Response Information by Rail
PHMSA
Final Rule Stage
Hazardous Materials: FAST Act Requirements for Flammable Liquids and Rail Tank Cars

The FAA


The Federal Aviation Administration (FAA) has 38 rulemakings listed in this version of the Unified Agenda. Unfortunately, none of those seems to address cybersecurity issues. While the FAA, aircraft manufacturers, and airlines are beginning to look at the potential risk from these issues, it does not appear that we are anywhere near regulatory considerations at this point.

I have selected three unmanned aerial system (UAS) rulemakings to include in my table. The first deals with flying small UAS over people and its abstract includes an interesting sentence; “This rulemaking would provide relief from certain operational restrictions implemented in the Operation and Certification of Small Unmanned Aircraft Systems final rule.” That rule prohibited the flying of small UAS over people.

The second rulemaking deals with the regulation of the operation of commercial small UAS. Since this rulemaking is supposed to look at registration and marking of small UAS, I included the third rulemaking which already addressed those issues in an interim final rule. The FAA still intends to issue a final rule on this topic.

NHTSA


The National Highway Transportation Safety Administration (NHTSA) has 25 rulemakings on the Unified Agenda. Only one of those may be of specific interest to readers of this blog, the vehicle-to-vehicle (V2V) rulemaking. That is because of the cybersecurity provisions that may be included in the rulemaking. I addressed these in my blog post on the ANPRM back in 2014; yes, NHTSA moves as fast as the rest of DOT in their rulemaking process.

PHMSA


The Pipeline and Hazardous Material Safety Administration (PHMSA) also has 25 rulemakings listed on the Unified Agenda. I selected four of those that deal, at least tangentially, with crude oil transportation by rail.

The first is a somewhat cooperative venture between PHMSA and the Federal Railroad Administration (FRA). This rulemaking would address results of an FRA study that identified “several trends in industry practices and operating procedures that present new and different risks to safety”. Addressing those risks and just generally updating the regulations regarding the handling of hazardous materials via rail should make for an interesting rulemaking.

The rail oil spill response plan rulemaking is high on the Congressional wish list and they have been applying pressure on PHMSA to complete this rulemaking. As would be expected, similar pressure is being exerted by a variety of environmental and safety activist organizations. Unfortunately, those two pressure points are pushing towards entirely different outcomes in the regulatory schema so I expect that we will see continued delays on this rulemaking.

The third PHMSA rulemaking was dictated by Congress in §7302 of the Fixing America's Surface Transportation (FAST) Act passed last December. It would require the creation of electronic train consists that include the identification of hazardous materials and emergency response information for those materials. Class 1 railroads are already developing/deploying this technology so PHMSA is behind the regulatory power curve.

The last rulemaking was also specified by the FAST Act in sections 7304, 7305, and 7306. In this case Congress was much more specific about what the rule should entail so PHMSA is going with a direct final rule without the publish and comment process to speed up their response to the Congressional requirement. Congress mandated that the final rule be published by May 16th, 2016, so PHMSA is already late on this rulemaking; no surprise here.

Long-Term Actions


While the DOT Unified Agenda is lengthy, they keep (with the exception of NHTSA) relatively few items on their long-term actions list. Only two items on their list made it to my list of interst:

OST
Protection of Sensitive Security Information
FRA
Track Safety Standards; Improving Rail Integrity

The first is included because both DHS and DOT have responsibility for protecting SSI and both have this on their long-term action list. Of course their continued inaction will mean that the SSI program will be more impacted by the National Archives and Records Administration rulemaking on sensitive but unclassified information that is in OIRA review.

At first glance I was severely disappointed to see this new rulemaking listed on the long-term actions page, but after a closer look I am just as confused as I am disappointed. Anyone that has followed the crude oil train issue in any detail will know that a large number of the crude oil train derailments that we have seen have been due, at least in part, by rail integrity issues. This rulemaking should be a priority for the FRA.


What makes me confused is that looking at the rulemaking page it shows that FRA intends to have a notice of proposed rulemaking (NPRM) ‘scheduled’ for June 2016. While I never believe projected dates in the Unified Agenda, that would indicate a fairly short-term long-term action. Oh well.

Thursday, January 14, 2016

NHTSA Sends V2V NPRM to OMB

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had received a notice of proposed rulemaking (NPRM) from the DOT’s National Highway Transportation Safety Administration (NHTSA) on vehicle to vehicle (V2V) communications. The advance notice of proposed rulemaking (ANPRM) for this was published in August 2014.

The Fall 2015 Unified Agenda describes the rulemaking this way:

“V2V communications uses on-board dedicated short-range radio communication (DSRC) devices to broadcast messages about a vehicle's speed, heading, brake status, and other information to other vehicles and receive the same information from the messages, with extended range and "line-of-sight" capabilities. V2V's enhanced detection distance and ability to "see" around corners or "through" other vehicles helps V2V-equipped vehicles uniquely perceive some threats and warn their drivers accordingly. V2V technology can also be fused with vehicle-resident technologies to potentially provide greater benefits than either approach alone. V2V can augment vehicle-resident systems by acting as a complete system, extending the ability of the overall safety system to address other crash scenarios not covered by V2V communications, such as lane and road departure. Additionally, V2V communication is currently perceived to become a foundational aspect of vehicle automation.”

This rulemaking may be the first place that NHTSA attempts to address cybersecurity issues related to automobiles. Based upon questions asked in the ANPRM it certainly looks like NHTSA has been looking at this as a potential vehicle for vehicle cybersecurity regulations.


There were over 900 comments received on the ANPRM in 2014. Surprisingly, a large number of them were from private citizens objecting to V2V implementation because of perceived health issues associated with electromagnetic radiation (EMR) from the radio transmissions involved in the communications. It will be interesting to see how NHTSA deals with those comments in this NPRM.

Wednesday, August 20, 2014

NHTSA Publishes V2V ANPRM

Today the DOT’s National Highway Transportation Safety Administration (NHTSA) published an advance notice of proposed rulemaking (ANPRM) in the Federal Register (79 FR 49270-49278) concerning potential creation of a Federal Motor Vehicle Safety Standard (FMVSS) for vehicle-to-vehicle (V2V) communications. NHTSA believes that requiring V2V communication capability in new light vehicles would facilitate the development and introduction of a number of advanced vehicle safety applications.

Along with the publication of this ANPRM NHTSA is publishing “Vehicle-to-Vehicle Communications: Readiness of V2V Technology for Application” (.PDF download link). According to the report abstract (pg i), the “report explores technical, legal, and policy  issues relevant to V2V, analyzing the research conducted thus far, the technological solutions available for  addressing the safety problems identified by the agency, the policy implications of those technological solutions, legal authority and legal issues such as liability and privacy”.

This ANPRM is not an actual proposal for any specific regulatory language; rather it asks a series of questions that NHTSA needs to have answered before it can proceed with the rulemaking process. The extensive list of questions covers ten general topics:


Of particular interest to readers of this blog will be the cybersecurity questions asked in the communications security section of the ANPRM. These questions include:

• Do commenters believe that using machine-to-machine PKI for V2V is feasible, and that a security system based on PKI provides the level of security needed to support wide-scale V2V deployment?
• Do commenters believe that the current security system design (as shown in Figure IX-3 of the research report) is a reasonable and sufficient approach for implementing a secure and trusted operating environment?
• Do commenters believe the Certificate Revocation List is necessary? 
• Do commenters believe a V2V system would create new potential “threat vectors” (i.e., “ways into” a vehicle's electronic control unit) that could somehow control a vehicle or manipulate its responses beyond those existing in today's vehicles?
• Do commenters believe that V2V could introduce the threat of remote code execution, i.e., that, among possible threat vectors, malicious code could be introduced remotely into a vehicle through the DSRC [dedicated short-range communications] device and could create a threat to affected vehicles?
• Do commenters have suggestions on how NHTSA could mitigate these potential threats with standardized security practices and how NHTSA could implement a self-certification or third-party audit or testing program to guard against such threats? 
• Does the absence of encryption of the Basic Safety Message itself create any security threat, e.g., reverse engineering of a V2V system?
• If OEM DSRC devices were kept up-to-date through the current methods of upgrading that existing consumer electronics use today, would the use of this updating process introduce a new attack vector?
• Is there a possibility of cyber-attacks across the entire vehicle fleet and, if so, how should they be analyzed and addressed?
• Are there any other specific security issues that have not been mentioned here, but that should be addressed in the V2V security review?


NHTSA is soliciting public responses to the questions listed in the ANPRM. Comments may be submitted via the Federal eRulemaking Portal (www.Regulations.gov; Docket # NHTSA-2014-0022). Comments should be submitted by October 20th, 2014.

Wednesday, August 13, 2014

OMB Approves NHTSA V2V Communications ANPRM

Yesterday the OMB’s Office of Information and Regulatory Affairs (OIRA) announced that it had approved the DOT’s National Highway Transportation Safety Administration’s (NHTSA) advanced notice of proposed rulemaking (ANPRM) on establishing a Federal Motor Vehicle Safety Standard (FMVSS) for vehicle to vehicle (V2V) communications.


This rulemaking was not included in the Spring Unified Agenda so it isn’t clear exactly what this rulemaking would encompass, but I suspect that it is related to the DOT’s Intelligent Transportation Systems Joint Program Office’s (ITSJPO) connected vehicle program. I last mentioned this program back in February. I expect that we will find out more details when the ANPRM is published, probably next week.
 
/* Use this with templates/template-twocol.html */