OTA Update (Over-the-Air Software Update)
An OTA update delivers new software to a vehicle over a wireless link instead of a workshop tester. How the chain works, what UN R156 requires and where ECUs fit in.
Updated This page as Markdown
In short
An OTA (over-the-air) update delivers new software or configuration to a vehicle over a wireless connection, usually cellular, instead of through a tester in a workshop. A backend packages and signs the update, the vehicle downloads it through its telematics unit, and an update master installs it on the target ECUs, often over the same UDS download services a workshop uses. UN R156 requires a software update management system and protection of the integrity and authenticity of updates.
What is an OTA update?
An OTA update is a software update that reaches the vehicle over a wireless link. It replaces or complements the workshop visit in which a tester flashes ECUs over the diagnostic connector.
The chain has three parts. A backend builds the update package, signs it and decides which vehicles receive it. The vehicle receives it through its telematics or connectivity unit. An update master inside the vehicle, often on the gateway or a central computer, checks the package and installs the contained software on the target ECUs, either over UDS download services or, on Linux and Android units, through A/B partitions that switch on the next boot.
Where is it defined?
UN R156 defines the regulatory requirements. Paragraph 7.1 covers the software update management system of the manufacturer, paragraph 7.2 the vehicle type, including protection of the update delivery against compromise and verification of authenticity and integrity, with additional requirements for over-the-air updates. UN R155 lists manipulation of software updates among the threats a manufacturer must address. On the ECU, the installation uses the UDS upload/download services from ISO 14229-1 or a manufacturer-specific mechanism.
What it means in practice
For ECU development, OTA mainly changes who triggers the programming path and how often. Every ECU that can be updated remotely needs a robust bootloader that verifies signatures, refuses unauthorized versions according to the manufacturer’s rollback policy, and survives an interrupted installation. The programming session, the SecurityAccess or authentication that guards it and the signature check in the bootloader are the parts that decide whether a manipulated package can reach the ECU.
OTA also matters after release: it is how vulnerabilities found by a VSOC or a researcher get fixed across a fleet without a recall to the workshop.
Common misunderstandings
OTA is not a security feature in itself; it is a delivery channel that has to be protected like any other. And an ECU that can be updated over the air still needs the same hardening of its diagnostic programming path, because the workshop route remains open.
FAQ
Frequently asked questions
What is the difference between SOTA and FOTA?
The terms are used loosely. SOTA usually means updating applications or software components, often on the infotainment or telematics unit; FOTA means replacing the firmware of an ECU. Both fall under UN R156 when they affect the vehicle type.
Does an OTA update bypass the ECU security?
It should not. On the ECU side the update usually arrives through the same programming path as a workshop flash: programming session, SecurityAccess or authentication, download and a signature check in the bootloader. OTA adds a remote delivery channel in front of that path, it does not replace it.
What does UN R156 require for OTA?
A certified software update management system at the manufacturer, protection of the integrity and authenticity of updates, and for OTA additional rules such as informing the driver and making sure the vehicle is in a safe state during installation.
Sources
Related pages
- GlossaryUN R156 (UN Regulation No. 156, Software Update)UN R156 is the UNECE regulation on software updates and the Software Update Management System. What it requires of OTA updates and how it connects to ECU testing.
- GlossaryProgramming Session (0x10 0x02)The UDS programming session (10 02) is the diagnostic mode for reflashing an ECU. How it is entered, which services it unlocks and why it is the most sensitive one.
- GlossaryRequestDownload (0x34)UDS RequestDownload (0x34) opens a download into ECU memory. Request bytes, maxNumberOfBlockLength, typical NRCs and why 0x34 outside a locked session is a top finding.
- GlossarySecure BootSecure boot verifies an ECU firmware image before it runs, so unsigned or modified software does not start. How it works, the HSM role and what a bench test can observe.
- GlossaryVSOC (Vehicle Security Operations Center)A VSOC monitors a vehicle fleet for cyber attacks and vulnerabilities after start of production. What it does, where UN R155 asks for it and how it links to bench tests.
