As part of a comprehensive approach to safeguard its vehicles from cyberattacks, Fiat Chrysler Automobiles (FCA US) has implemented a Secure Gateway (SGW) module in the electrical architecture, starting with most 2018 Model Year vehicles. This module functions as a secure firewall that protects external access to the vehicle via the radio and diagnostic connector from the rest of the vehicle network.
The SGW gates all data exchanged between the “outside world” (e.g., diagnostic tools, incoming signals to radio/head unit) and the “vehicle”, and it determines what commands to allow through the Gateway based on an approved list. The SGW does not restrict access to diagnostic data. It restricts the ability of non-registered and non-authenticated users to perform intrusive diagnostics such as bi-directional controls. The SGW can control the level of access for each user, based on an assigned role determined during an authentication process. A challenge-response protocol is used for Authenticated Access. A similar process is used for FCA US franchised dealerships.
AutoAuth AutoAuth is the authentication solution created to give Independent Aftermarket (IAM) Tools the ability to unlock the SGW using the authentication process and perform all applicable diagnostic repairs. The entire solution consists of two systems: 1) the “User Management System,” and 2) the “SGW Authentication Bridge Server,” that collectively provides the ability for Independent Aftermarket (IAM) Diagnostic Tools, Users (e.g., independent technicians), and Shops to perform an account registration process and the SGW authentication process.
SGW Authentication Bridge Server The SGW Authentication Bridge Server acts as a “bridge” to allow IAM tools the ability to retrieve necessary information from FCA’s Public Key Infrastructure (PKI) to perform the authentication process with the SGW. It provides separation between FCA US internal systems and IAM Tool Manufacturer systems for architecture and security purposes. Only those IAM Tool Manufacturers who enter into the required legal agreements with FCA US, as governed by FCA US MOPAR Technical Service Operations will be allowed to interface with the SGW Authentication Bridge.
Country of Origin | United States of America (USA) |
Model Number | 01 |
What's In The Box | 1X DEVICE 1X BAG 1X FCA ACCOUNT |
Model Name | TKD |