🤖 AI Summary
This work proposes the first safety-certifiable, persistent hot-patching framework compliant with automotive functional safety standards such as ISO 26262, enabling rapid vulnerability remediation without requiring full firmware re-flashing. Addressing the limitations of existing hot-patch solutions—which struggle to simultaneously ensure regulatory compliance, runtime safety, and compatibility with Flash-based execute-in-place (XIP) architectures—the proposed method is specifically designed for XIP environments and integrates seamlessly with real-time operating systems including FreeRTOS and Zephyr. Implemented and validated on the automotive-grade NXP S32K148EVB platform, the framework incurs only a 3.3-microsecond patching overhead and a 6.34% firmware size increase while successfully mitigating multiple real-world CVEs. Experimental results demonstrate a significant reduction in mean time-to-mitigation (MTTM) without compromising system determinism or resource efficiency.
📝 Abstract
The increasing presence of software in modern automobiles has created a growing need to deliver software updates throughout a vehicle's entire lifespan. Traditional update methods are slow and require months of re-validation to comply with stringent safety standards like ISO 26262. Although hotpatching offers a path to faster updates, existing solutions for real-time embedded systems are unsuitable for the automotive domain: they overlook regulatory compliance, demand extensive safety validation, and lack support for the flash-based Execute-in-Place (XIP) architecture commonly used in automotive electronic control units (ECUs).
We introduce Patchlings, the first hotpatching framework designed for compliance, safety, and persistence in automotive systems. It fills the gap in applying hotpatching to automotive systems and fundamentally reduces the mean-time-to-mitigate (MTTM) for vulnerabilities and bugs. We implement and evaluate a complete prototype of Patchlings on an automotive-grade hardware platform, NXP S32K148EVB, with both FreeRTOS and Zephyr. Our results demonstrate low and deterministic overhead (e.g., 3.3 $μ$s when a patch is applied), small firmware size increase (e.g., as low as 6.34%), and successful patching of different types of real CVEs, proving its real-world applicability and effectiveness.