Thank you very much to the committee for giving me the opportunity to speak.
I'm a professor in the department of electrical and computer engineering at the University of Waterloo. I've been working for about 26 years in the area of safety and security of cyber-physical systems across different sectors.
I've also spun off multiple companies out of R and D at the university. The notable one that might be of interest to this committee is Palitronica, which provides supply chain cybersecurity solutions and cyber-assurance to detect defects, oversights, fraud and cybersecurity issues in the supply chain.
I want to bring up and raise awareness of a particular problem that prior witnesses have not really mentioned yet, which is around potential systematic compromises of systems, like vehicles, through the supply chain.
Supply chain attacks, as they are typically known, are classified under Mitre ATT&CK and allow the attacker to insert vulnerabilities before systems are delivered and deployed. This enables coordinated, large-scale exploitation of these exploited systems at a time of the adversary's choosing. In the context of vehicles and charging infrastructure, this could mean maliciously inserted and embedded circuits in battery management systems or compromised charging systems to destabilize the grid, for example, at a point of their choosing.
Public literature already documents real-world examples of hardware tampering and supply chain compromises across a number of industries. There are examples from public literature: USB devices rigged with explosives sent to journalists in Ecuador and bypass electronics in commercial off-the-shelf switches that allow you to load arbitrary firmware onto these systems. You can go on the Internet right now and buy cables and keyboards that look like regular keyboards but actually have hardware implants in them that allow you to steal data from phones and computers.
A viable response to this risk is the zero-trust supply chain model, in which no component is implicitly trusted regardless of its origin. Every part is verified, measured and continuously assessed. We already do this today. When you go to the airport, regardless of who you are, your bags are scanned with an X-ray scanner. No matter where you're from, no matter how often you've flown, your bags are being scanned; past behaviour does not eliminate present risk.
The technology to implement these zero-trust systems is already present and is deployed today by leading companies in high-assurance sectors, such as aerospace and defence. Unfortunately, Canada is lagging behind in adoption, and that leaves Canadians exposed to supply chain risks in a particular area, like, for example, in automotive.
The urgency of supply chain assurance techniques is only increasing. Today, AI solutions allow for the rapid generation of software, and hardware will follow. What this means is that in the near future, malicious actors will be able to generate counterfeit or malicious automotive components by pressing a button. Put simply, as right now you can go into ChatGPT solutions and say, “Give me an answer or a summary of this”, you will be able to clone hardware and will be able to add and create malicious circuits. When that happens, supply chains built on trust and good feelings will fail. Only supply chains using zero-trust principles will remain secure.
A fundamental question is whether we choose to lead or wait until the news catches up with us. Naturally, I advocate for Canada to adopt zero-trust principles for supply chains in automotive and other areas before security incidents force us to do so.
Thank you very much.
