Skip to main content

Regulation Update

AIS 190 and Software Update Management in India

The Indian counterpart to UNECE R156. If your update process cannot say what software is on a given vehicle, this is the requirement that will expose it.

Article details

Category
Regulation Update
Published
Reading time
6 min read
Author
AutoSec Academy · Compliance Practice

AIS 190 addresses software update management for the Indian market, mirroring the intent of UNECE R156: an update must not compromise safety, must not silently invalidate a type approval, and must be traceable to the vehicles that received it.

Configuration traceability is the hard part

The security controls around an update — signing, integrity verification, rollback protection — are usually in reasonable shape. What fails assessment is the record-keeping: identifying, for any given vehicle, exactly which software versions are installed and which approved configuration they correspond to.

  • A software identification scheme that survives supplier part changes
  • Records linking vehicle identity to installed versions
  • An assessment of whether a given update affects type-approval relevant parameters
  • A defined and tested rollback path

As with AIS 189, confirm applicability and timelines through the Indian regulatory process; the requirements are revised as the framework matures.

Back to the Knowledge Center

Stay current

Get the Next One in Your Inbox

Regulatory updates and lab research, sent when there is something worth saying.

Threat intelligence, straight to your inbox

Regulatory updates, lab research and new program announcements. No noise.

What should we send you?

Go Deeper Than an Article

The programs behind this analysis put you on real ECU hardware, with practitioners who do this work for a living.