Comillas Pontifical University. Madrid (Spain)
December 17th, 2025
Summary:
The automotive industry has been a prime target for cybercriminals for decades, with attacks becoming increasingly sophisticated as vehicles integrate advanced digital technologies. Modern vehicles present an extensive attack surface due to the growing number of interconnected electronic components and wireless communication features. While these technologies improve connectivity, automation, and comfort, they also introduce new vulnerabilities that can be exploited by attackers. In response, new standards and regulations require manufacturers to implement robust cybersecurity measures to obtain required certifications. This dissertation explores the attack surface of modern vehicles by analyzing several critical systems and technologies.
First, a comprehensive study of wireless communication technologies is presented, highlighting existing research, known vulnerabilities, and potential countermeasures, while identifying key research gaps that require further investigation. In addition, background about Bluetooth and OBD-II dongles is presented; as well as concepts related to Vehicle to-Everything (V2X) communications.
Second, Remote Keyless Entry (RKE) protocols are examined, with the identification and analysis of a vulnerability that enables key fob cloning through a black-box reverse engineering methodology. This approach relies solely on open-source tools and commercially available hardware, avoiding the need for expensive firmware extraction tools. This methodology is applied to eight protocols from different manufacturers, trying to determine the protocol structure. As a result, a detailed analysis of eight protocols from different manufacturers is shown and they are compared from a security perspective, with one of them being totally broken.
[...]
Spanish layman's summary:
Esta tesis doctoral analiza cómo la digitalización del automóvil ha ampliado su exposición a ciberataques. Estudia vulnerabilidades en mandos a distancia, dispositivos OBD-II y sistemas V2X, demostrando ataques reales y proponiendo medidas para mejorar la seguridad de los vehículos del futuro.
English layman's summary:
This doctoral thesis analyzes how the digitalization of automobiles has increased their exposure to cyberattacks. It studies vulnerabilities in remote key fobs, OBD-II devices, and V2X systems, demonstrating real attacks and proposing measures to improve the security of future vehicles.
Descriptors: Motor vehicle technology, Telecommunications technology, Radiocommunications, Transportation systems technology
Keywords: Cybersecurity, Vehicles, Radio frequency, Reverse engineering, Remote Keyless Entry, Car Hacking, Bluetooth, OBD-II, RKE, V2X, Cooperative Awareness, Replay Attack, Pseudonym, Simulation
Citation:
R. Gesteira-Miñarro, "Analysis of Cybersecurity Systems in the Automotive Sector", PhD. dissertation, Comillas Pontifical University, Madrid, Spain, 2025.