SDV SectorNews and signals from the software-defined vehicle sector. Global coverage, daily.

China put a vehicle intrusion-detection standard out for comment

A draft recommended national standard sets out what an in-vehicle intrusion detection system has to catch across the operating system, the external interfaces, the CAN and Ethernet buses and the off-vehicle links, and requires security logs to be kept for at least six months.

Detailed shot of Ethernet cables connected to server ports highlighting technology infrastructure.
Illustrative photo · Brett Sayles / Pexels · not the vehicle described

China’s intelligent and connected vehicle standards subcommittee opened public comment on September 24 on a draft recommended national standard for vehicle cybersecurity intrusion detection, under plan number 20255714-T-339.

The draft applies to M- and N-category vehicles fitted with an intrusion detection function, and divides the requirements into four domains. On the vehicle operating system it asks for detection of malware, abnormal open ports, secure-boot failure, brute-force login attempts, tampering with authentication data and system configuration files, unauthorized application installation, and applications taking camera or microphone permissions. On external interfaces it covers unauthorized USB devices, malicious diagnostic traffic such as reset commands, and debug mode being opened.

For in-vehicle communication the draft separates automotive Ethernet from CAN. Ethernet requirements include port scans, denial-of-service patterns and replay, and a system should be able to detect abnormal UDS requests. On CAN and CAN FD it asks for bus-load denial of service, cycle anomalies, freshness-value replay detection, data-length validity, CAN identifiers appearing outside a whitelist on the wrong bus, and signal-sequence checks. The fourth domain covers off-vehicle links: spoofed vehicle-to-everything position or traffic-signal data, Bluetooth pairing abuse, wireless brute force, radio and near-field replay, and cellular denial of service.

Security logs should be retained for no less than six months, and uploads to the cloud should authenticate the peer and protect integrity, with TLS 1.2 or the Chinese TLCP 1.1 named as examples. Transmission should be resumable so logs are not lost.

The document is proposed by the industry ministry and administered by the national automotive standardization committee. Drafting units named on it include Dongfeng, Changan, BYD, Geely, Great Wall, FAW, GAC, SAIC, Beijing Li Auto, Huawei’s Yinwang automotive unit and Baidu’s Apollo arm, alongside CATARC and state testing institutes.

A recommended national standard is not mandatory.

Why it mattersIt is the first Chinese national standard to put testable intrusion-detection duties on a production vehicle, and it specifies them per bus and per interface rather than leaving the implementation to the manufacturer.

Source: SAC/TC114/SC34 consultation notice 2026-征求意见-018 (CATARC standards portal)

The SDV Sector Brief

The month in vehicle software — top stories, what our readers read most, and an editor's take. First Tuesday of the month, 08:30 CET. Double opt-in, unsubscribe anytime.