CarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Notification
  • Autonomous Driving
  • Automotive Ethernet
  • BMS
  • ECU
  • EV
  • ISO/SAE 21434
  • Infotainment
  • OTA Updates
  • OBD-II
  • Pwn2Own
  • RCE
  • SDVs
  • TCU
  • UNECE R155
Cybersecurity

St. Paul pulls plate reader cameras after data reached immigration agents

Policy & Compliance

China freezes vehicle software to end patch-later OTA era

Policy & Compliance

NRMA and Lexus Australia push Canberra toward car data law

Policy & Compliance

Quebec report declares car data consent fundamentally broken

Font ResizerAa
CarThreatCarThreat
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
Search
  • Home
  • News
  • Features
  • Spotlight
  • Events
  • About
    • Our Mission
    • Services
    • Contact
Sign In Sign In
Follow US
© 2026 Carthreat.com. All right reserved.
Cybersecurity

Patch mechanism updates embedded ECUs without dual-bank flash

Patchlings gives deeply embedded ECUs rollback-safe updates without the dual-bank flash most designs assume.

CarThreat Staff
Last updated: August 13, 2026 10:58 pm
By
ctadmin
2 Min Read
SHARE

Bosch researcher Sekar Kulandaivel has developed Patchlings, an update mechanism that lets deeply embedded ECUs receive secure patches without the dual-bank flash memory most designs assume, a constraint that blocks many vehicles from meeting UN R155 and R156 update mandates.

Modern regulations require automakers to support long-term updates, including ECUs never designed for post-deployment patching. The usual answer is dual-bank flash, where two copies of firmware let a system roll back on failure. That approach is costly and impractical for many single-bank platforms.

Patchlings keeps the original firmware as an immutable baseline and redirects bounded control flow to a dedicated patch region. A dual-sector redirection-table commit gives A/B-equivalent power-fail safety with atomic activation, and the mechanism supports both bootloader and application updates without rewriting validated software.

The researcher validated the design through implementation and power-fail testing on an NXP S32K board, and presented the work at VehicleSec ’26.

The approach matters as regulators push software-defined vehicles: update capability is now a compliance requirement, and automakers need patch paths that fit cheap, memory-constrained ECUs rather than hardware redesigns. Making rollback-safe updates affordable for the whole vehicle, not just flagship controllers, is what lets the industry close the gap between regulation and reality.

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
TAGGED:Automotive CybersecurityCybersecurityECU SecurityFirmware SecurityOTA UpdatesUNECE R155
SOURCES:USENIX VehicleSec 2026
Share This Article
Facebook Email Copy Link

Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe

You Might Also Like

Cybersecurity

Extortion group Helix claims a million files from Uber Freight

By
ctadmin
August 13, 2026
Cybersecurity

Rogue SIM cards hijack EV chargers through a hidden modem command

By
ctadmin
August 12, 2026
Cybersecurity

License plate camera firm locks down vehicle data after abuse reports

By
ctadmin
August 17, 2026
PCA finds 345 auto vulnerabilities as high-severity flaws double
Cybersecurity

PCA finds 345 auto vulnerabilities as high-severity flaws double

By
ctadmin
August 1, 2026
Cybersecurity

Report warns supplier hacks could cost automakers $100M

By
ctadmin
August 14, 2026
Research & Innovation

Fake brake alerts in V2X networks can trigger phantom stops

By
ctadmin
August 9, 2026

CarThreat

Intelligence for the EV and automotive security market
  • News
  • Features
  • Spotlight
  • Events
  • About Carthreat
  • Our Mission
  • Services
  • Contact Us
  • OBD-II
  • Automotive Ethernet
  • TCU
  • Infotainment Systems
  • SDVs
  • BMS
  • ECU Security
  • CAN Bus
  • Threat Intelligence
  • Cybersecurity
  • Digital Keys
  • Bluetooth Security
  • OTA Updates
  • Vulnerabilities
  • Relay Attacks
  • RCE
  • Data Privacy
  • EVs
  • Autonomous Driving
  • Pwn2Own Automotive
  • ISO/SAE 21434
  • UNECE R155
  • Regulations

© 2026 Carthreat.com. All right reserved.  Privacy Policy | Legal

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?