Skip to content
Use case 002

Vehicle Cybersecurity Gateways

A deployment concept for Vehicle OEMs setting gateway security requirements; Tier 1 gateway manufacturers embedding system software; Vehicle architecture integrators adapting legacy networks.

Proposed deployment · Compatibility assessment required
Automotive and Road Mobility

Why this environment matters

A vehicle gateway decides whether a message arriving through telematics, entertainment or a workshop connection may reach another vehicle network. The important distinction is between carrying a diagnostic request and granting permission to perform the requested operation. This concept examines that boundary; it does not propose replacing braking or steering controllers.

The security challenge

Consider a service technician reading fault codes while the telematics unit remains connected to a remote backend. A generic network tunnel can make both paths look equally trusted once traffic reaches an internal bus. The design question is which component can originate a diagnostic operation, against which electronic control unit, and in what vehicle state.

How the capsule model could help

A NØNOS prototype would place external protocol parsers in separate capsules and send typed diagnostic requests to a small policy broker. The broker would check the requested service, target controller and session authority before a dedicated adapter transmits anything. Reading a fault code would not confer permission to flash firmware or actuate a component. Gateway isolation is useful only if rejected traffic cannot starve the routes the vehicle needs. The evaluation would therefore reserve resources for essential forwarding, rate-limit diagnostic work and exercise malformed messages while normal bus traffic continues. A parser restart should discard its temporary session authority without clearing unrelated control state. An apparently valid request can still be unsafe. Vehicle state may be stale, an authorised workshop credential may be stolen, or the permitted command itself may be inappropriate. Independent controller protections and service procedures remain part of the design. Memory-safe parsing addresses a narrower class of software faults.

Separate address spaces and capability checks can limit cross-process reach. They cannot stop harmful use of legitimate permissions, prove AI decisions correct or substitute for domain-specific safety controls.

Deployment requirements

Feasibility depends on vehicle-specific bus drivers, scheduling and diagnostic integration. Bench results would not establish automotive functional-safety approval or show that any particular vehicle intrusion would have been prevented. Evaluation requirements: Attempt a firmware-write service through a session approved only to read faults; the request should be denied before bus transmission. Restart the external parser under peak diagnostic traffic and measure whether essential forwarding deadlines remain satisfied. Revoke a workshop session, then replay its previously accepted request and verify that authority has actually expired.

Current public-beta limitations, hardware support and application availability must be assessed before any pilot. Neither this use case nor an industry source establishes NONOS certification or a current customer deployment.

A diagnostic session with more authority than its transport

Consider a service technician reading fault codes while the telematics unit remains connected to a remote backend. A generic network tunnel can make both paths look equally trusted once traffic reaches an internal bus. The design question is which component can originate a diagnostic operation, against which electronic control unit, and in what vehicle state.

A NØNOS prototype would place external protocol parsers in separate capsules and send typed diagnostic requests to a small policy broker. The broker would check the requested service, target controller and session authority before a dedicated adapter transmits anything. Reading a fault code would not confer permission to flash firmware or actuate a component.

Preserve essential traffic during a parser failure

Gateway isolation is useful only if rejected traffic cannot starve the routes the vehicle needs. The evaluation would therefore reserve resources for essential forwarding, rate-limit diagnostic work and exercise malformed messages while normal bus traffic continues. A parser restart should discard its temporary session authority without clearing unrelated control state.

An apparently valid request can still be unsafe. Vehicle state may be stale, an authorised workshop credential may be stolen, or the permitted command itself may be inappropriate. Independent controller protections and service procedures remain part of the design. Memory-safe parsing addresses a narrower class of software faults.

Who could buy or integrate it?

  • Vehicle OEMs setting gateway security requirements
  • Tier 1 gateway manufacturers embedding system software
  • Vehicle architecture integrators adapting legacy networks

Industry examples: Aptiv, Bosch. Organisations shown illustrate the industry. No NONOS customer, partner or endorsement relationship is implied.

Market opportunity

Market benchmarks and device scenarios.

Published industry benchmark
US$33 billion

Automotive software

Global · 2025 · annual market estimate

Vehicle applications, operating systems and middleware across passenger and commercial vehicles; not solely security.

Modelled global devices
150M–500M

Candidate OS endpoints

Hypothetical planning range · 2025

Low confidence: planning assumptions. Hardware compatibility, procurement and adoption have not been validated.

Illustrative annual licensing
$300M–$7.5B

USD / year at full model coverage

Device scenario × assumed US$2–$15 per device / year.

Not a revenue forecast, announced price or measured serviceable market.

Device calculation

Hypothetical global planning range, 2025 scenario: assume 150,000,000–500,000,000 vehicles with software-updatable central network gateways × 1–1 candidate OS endpoints per site/asset = 150,000,000–500,000,000 endpoints. Counting unit: one vehicle security gateway; excludes individual ECUs. Site and asset counts, and devices per site, are planning assumptions. The installed base has not been measured. Coverage is limited to the defined equipped subset; includes all candidate endpoints within that assumed subset. Hardware eligibility, certification, adoption and achievable NØNOS share are unverified; overlaps other cases.

Automotive software market report ↗

Market context only; separate from device and site population estimates. Original monetary-market scope and geography are preserved in benchmark. This source does not establish the assumed worldwide site count or endpoint density.

How to interpret the figures

Adjacent or broader commercial market benchmark; not the NØNOS OS market, licensable-device count or revenue forecast.

Modelled candidate endpoints multiplied by an assumed annual USD price per endpoint. Pricing is a planning assumption, not a vendor quote. This illustrates the full scenario range, not revenue or total addressable market. It excludes adoption timing, procurement, certification, support costs, channel economics and achievable market share. Use cases can overlap, so their totals do not represent unique devices.

Research from 2026. Publisher estimates have not been independently audited.

Read the full methodology

Explore NONOS

Choose your
NONOS experience.

Discover the platform for your organisation or explore the software.

You can reopen this chooser from the footer at any time.