SlideShare a Scribd company logo
The connected car App experience
Improving consumer adoption through secure APIs
6/4/2014
© 2014 CA. All rights reserved.
Francois Lascelles
VP Solutions Architecture, CA Technologies
2 © 2014 CA. ALL RIGHTS RESERVED.
Mobile
Car
3rd party
service/soc
ial
Connected
Car Service
Provider
How do you connect
any of these things?
The connected car
Connected to what?
 Manufacturer or service provider
– Telemetry, call home
 Entertainment platforms
– E.g. Netflix
 Weather, traffic info, gps
 Social media
 A mobile app used by driver
3 © 2014 CA. ALL RIGHTS RESERVED.
Connections = APIs
Web
Web API
 Presentation, interface
 Information
 Information Presentation, interface
{ “min”: “23C”,
“max”: “11C”…}
4 © 2014 CA. ALL RIGHTS RESERVED.
APIs connect everything
{ “min”: “23C”,
“max”: “11C”…}
5 © 2014 CA. ALL RIGHTS RESERVED.
Mobile
Car 3rd party
service/soc
ial
Connected
Car Service
Provider
APIs of the connected car
APIs
APIs
APIs
App
App
App
6 © 2014 CA. ALL RIGHTS RESERVED.
Connected car user experience
In-car/IHU apps
Emerging/immature app marketplace
Closed ecosystem
Mobile apps
Mature app marketplace
Rich experience
7 © 2014 CA. ALL RIGHTS RESERVED.
Mobile
Car 3rd party
service/soc
ial
Connected
Car Service
Provider
Companion app
APIs
APIs
APIs
{ unlock}
{ unlock}
8 © 2014 CA. ALL RIGHTS RESERVED.
Companion App
9 © 2014 CA. ALL RIGHTS RESERVED.
Mobile
Car 3rd party
service/soc
ial
Connected
Car Service
Provider
Mobile powered car sharing service
APIs
APIs
APIs
{book it}
{pickup}
{find it}
10 © 2014 CA. ALL RIGHTS RESERVED.
Good UX -> good business
UX
Adoption
11 © 2014 CA. ALL RIGHTS RESERVED.
Security matters too
 Safety
– When cars can be controlled
remotely …
“My car was hacked”
 Privacy
– Locate users
– Abuse of driver history data
APIs are becoming
the attack vector of
choice for the new
generation of hackers
12 © 2014 CA. ALL RIGHTS RESERVED.
UX Disruptors
 Key defensive techniques, such as user
authentication disrupt UX
 The impact on user experience is more
severe in mobile context
 Compounding factors:
– Challenge frequency
– Number of secrets
– Secret complexity
13 © 2014 CA. ALL RIGHTS RESERVED.
Reconciling UX and Security
Identify
yourself
Show me my
data
14 © 2014 CA. ALL RIGHTS RESERVED.
Public vs confidential apps
 Public devices and public clients shift burden of
authentication to a user (lowering UX)
– Pattern: Secure API flows which assert registered device/client
Mobile
Connected
Car Service
Provider
{prove
possession}
Register
device, app
In-car appHSM
15 © 2014 CA. ALL RIGHTS RESERVED.
User-managed delegation
 Users delegate applications to act on their behalf
– Pattern: revocation should be as easy as delegation
Connected
Car Service
Provider
… later, device lost or stolen
Connected
Car Service
Provider
Revoke app,
device
Authorize
app, device
16 © 2014 CA. ALL RIGHTS RESERVED.
Risk and context-based authorization
 Low
– Must have valid session
 Medium
– Must have a ‘fresh’ session
 High
– Registered device only
– Challenge user every x minutes
Risk
associated
with API
call
 Multifactor
– Infotainment + mobile
17 © 2014 CA. ALL RIGHTS RESERVED.
API-enabled connected car service provider
 Beyond enhancing the user experience,
APIs enable new business and partnership
 250M connected cars = big data
– Telemetry history
– APIs lets you monetize this information
Driving new business models and partnerships
Insurance
Urban planning
Emergency
response
Real-time traffic
info
 Connected car API
infrastructure
– Correlate
– Anonymize
– Secure
[your idea here]
18 © 2014 CA. ALL RIGHTS RESERVED.
API infrastructure for the connected car
 Enable innovation
Layer 7 API Management Solutions
App developer services
Internal/3rd party
developer on boarding
API discovery
App registration
API Key issuing
Analytics
Billing
Mobile SDKs
Runtime API services
Secure API delivery
Access control
Enterprise integration
Identity brokering
Device registration
Social/cloud integration
Threat protection,
sanitization
 Deliver, scale and
secure
19 © 2014 CA. ALL RIGHTS RESERVED.
Thank you
© 2014 CA. All rights reserved.
Francois Lascelles
VP Solutions Architecture, CA Technologies

More Related Content

PPTX
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
PPTX
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
PDF
WSO2 @ Connected Car
PDF
Building Beautiful High Performance Connected Car Applications
PPTX
Connected Car Services - Generalizing and Simplifying Telematics
PDF
TaxiStartup deck
PDF
Icabs - a taxi compliance & inspection mobile application system for irelands...
PDF
Deployment of Beacon Technology in Aviation by Leantegra
Panel Session: Security & Privacy for Connected Cars w/ Scott Morrison, SVP ...
APIs Fueling the Connected Car Opportunity - Scott Morrison, SVP & Distinguis...
WSO2 @ Connected Car
Building Beautiful High Performance Connected Car Applications
Connected Car Services - Generalizing and Simplifying Telematics
TaxiStartup deck
Icabs - a taxi compliance & inspection mobile application system for irelands...
Deployment of Beacon Technology in Aviation by Leantegra

What's hot (20)

PDF
Taxify engineering presentation - DevTernity
PPTX
6 common front end features of taxi dispatch system by your cab manager
PPT
Emerging technologies in_business
PDF
Ancilliary Revenue - Your Ticket to Profit
PPTX
T Dispatch - Taxi Dispatch System
PPTX
Introduction to si tech ci c mobile engine
PDF
Symphony Teleca - The Connected Car Revolution @ Cebit 2014
PDF
Open API at Transavia
PPTX
Connected Car Investment Thesis
PDF
Sept2015Connected Car short
PPTX
The Connected Car is Here
PPTX
Cab booking system india
PPTX
Ashley Horvat, PlugShare - EV Charging Snapshot
PPTX
Alexa and the Connected Car
PDF
KaCyber Brochure
PPTX
Railmitra B-Plan
PPTX
online Cab Booking System PPT Presentation
PDF
Ake parking guidance system
PPTX
App Proposals - Cab Booking
PDF
New way to do Business for Load Brokers
Taxify engineering presentation - DevTernity
6 common front end features of taxi dispatch system by your cab manager
Emerging technologies in_business
Ancilliary Revenue - Your Ticket to Profit
T Dispatch - Taxi Dispatch System
Introduction to si tech ci c mobile engine
Symphony Teleca - The Connected Car Revolution @ Cebit 2014
Open API at Transavia
Connected Car Investment Thesis
Sept2015Connected Car short
The Connected Car is Here
Cab booking system india
Ashley Horvat, PlugShare - EV Charging Snapshot
Alexa and the Connected Car
KaCyber Brochure
Railmitra B-Plan
online Cab Booking System PPT Presentation
Ake parking guidance system
App Proposals - Cab Booking
New way to do Business for Load Brokers
Ad

Viewers also liked (11)

PDF
Designing UI/UX for Mobile-Connected Devices
PDF
Connected Car by Ashish Bhasin
PPTX
MONETIZING THE CONNECTED CAR, Citi 2013 Connected Car Symposium
PDF
Ux trend report 2014 connected_car
PDF
Connected Car Security and the Future of Transportation
PDF
Case Study: General Motors Drives Innovation With APIs to Perfect the Connect...
PDF
The Connected Car: Driving Towards the Future
PDF
Connected car 중심의 2016 UX 트렌드
PPTX
The Internet of Cars - Towards the Future of the Connected Car
PDF
25 Cars Worth Waiting For 2016–2019
PDF
UX for connected cars
Designing UI/UX for Mobile-Connected Devices
Connected Car by Ashish Bhasin
MONETIZING THE CONNECTED CAR, Citi 2013 Connected Car Symposium
Ux trend report 2014 connected_car
Connected Car Security and the Future of Transportation
Case Study: General Motors Drives Innovation With APIs to Perfect the Connect...
The Connected Car: Driving Towards the Future
Connected car 중심의 2016 UX 트렌드
The Internet of Cars - Towards the Future of the Connected Car
25 Cars Worth Waiting For 2016–2019
UX for connected cars
Ad

Similar to The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architect, CA Layer 7 @ Telematics Detroit (20)

PDF
Enabling the Multi-Device Universe
PDF
Creating the Borderless Workplace
PDF
Adapting to Digital Change: Use APIs to Delight Customers & Win
PDF
CA API Management: A DevOps Enabler
PPTX
Leveraging Technology for Government Service Delivery
PDF
DevOps for Mobile: Delivering a 5-Star App Experience to Your Mobile Users
DOCX
RAJEEV_SEN_RESUME
PDF
Enable and Secure Business Growth in the New Application Economy
PDF
How Much Does It Cost To Develop An Uber-Style App? - AppsDevPro
PPTX
Trust No One: The New Security Model for Web APIs - SecTor talk by Greg Kliew...
PPTX
CA Mobile Application Analytics - Julio 2015
PDF
Building Real-time Push APIs Using Kafka as the Customer Facing Interface wit...
PPTX
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
PDF
IoE = New Partners & Business Models @ ITS World Congress 2014
PPTX
Air API | Airline Data API | GDS Flight API Integration
PDF
Deployment of Beacon Technology in Aviation by Leantegra
PDF
AppSphere 15 - Turning to Unified Monitoring & Real-time Application Analytics
PDF
Using APIs to Create an Omni-Channel Retail Experience
PDF
CA - Entrega Continua
PDF
ChargeHub Empowering Electric Mobility
Enabling the Multi-Device Universe
Creating the Borderless Workplace
Adapting to Digital Change: Use APIs to Delight Customers & Win
CA API Management: A DevOps Enabler
Leveraging Technology for Government Service Delivery
DevOps for Mobile: Delivering a 5-Star App Experience to Your Mobile Users
RAJEEV_SEN_RESUME
Enable and Secure Business Growth in the New Application Economy
How Much Does It Cost To Develop An Uber-Style App? - AppsDevPro
Trust No One: The New Security Model for Web APIs - SecTor talk by Greg Kliew...
CA Mobile Application Analytics - Julio 2015
Building Real-time Push APIs Using Kafka as the Customer Facing Interface wit...
Balancing Security & Developer Enablement in Enterprise Mobility - Jaime Ryan...
IoE = New Partners & Business Models @ ITS World Congress 2014
Air API | Airline Data API | GDS Flight API Integration
Deployment of Beacon Technology in Aviation by Leantegra
AppSphere 15 - Turning to Unified Monitoring & Real-time Application Analytics
Using APIs to Create an Omni-Channel Retail Experience
CA - Entrega Continua
ChargeHub Empowering Electric Mobility

More from CA API Management (20)

PDF
Api architectures for the modern enterprise
PDF
Mastering Digital Channels with APIs
PDF
Takeaways from API Security Breaches Webinar
PDF
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
PDF
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
PDF
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
PPTX
API Monetization: Unlock the Value of Your Data
PDF
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
PDF
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
PDF
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
PDF
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
PDF
5 steps end to end security consumer apps
PPTX
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
PDF
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
PPTX
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
PDF
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
PPTX
Is there an API in that (IoT)?
PPTX
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
PDF
Your New Digital Business & APIs
PDF
Mapping the API Landscape - Mike Amundsen, Director of API Architecture
Api architectures for the modern enterprise
Mastering Digital Channels with APIs
Takeaways from API Security Breaches Webinar
API Design Methodology - Mike Amundsen, Director of API Architecture, API Aca...
Liberating the API Economy with Scale-Free Networks - Mike Amundsen, Director...
API360 – A How-To Guide for Enterprise APIs - Learn how to position your ente...
API Monetization: Unlock the Value of Your Data
Revisiting Geddes' Outlook Tower - Mike Amundsen, Director of API Architectur...
Managing Identity by Giving Up Control - Scott Morrison, SVP & Distinguished ...
Building APIs That Last for Decades - Irakli Nadareishvili, Director of API S...
The Art of API Design - Ronnie Mitra, Director of API Design, API Academy at ...
5 steps end to end security consumer apps
Best Practices You Must Apply to Secure Your APIs - Scott Morrison, SVP & Dis...
Drones, Phones & Pwns the Promise & Dangers of IoT APIs: Use APIs to Securely...
Gartner AADI Summit Sydney 2014 Implementing the Layer 7 API Management Pla...
Clients Matter, Services Don't - Mike Amundsen's talk from QCon New York 2014
Is there an API in that (IoT)?
Truth, Lies & APIs - Ross Garrett, Director Product Marketing, CA Layer 7 @ G...
Your New Digital Business & APIs
Mapping the API Landscape - Mike Amundsen, Director of API Architecture

Recently uploaded (20)

PDF
NewMind AI Weekly Chronicles - August'25 Week I
PDF
KodekX | Application Modernization Development
PPT
Teaching material agriculture food technology
PPTX
Cloud computing and distributed systems.
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Machine learning based COVID-19 study performance prediction
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PPTX
A Presentation on Artificial Intelligence
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Empathic Computing: Creating Shared Understanding
NewMind AI Weekly Chronicles - August'25 Week I
KodekX | Application Modernization Development
Teaching material agriculture food technology
Cloud computing and distributed systems.
Encapsulation_ Review paper, used for researhc scholars
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
“AI and Expert System Decision Support & Business Intelligence Systems”
Diabetes mellitus diagnosis method based random forest with bat algorithm
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
MYSQL Presentation for SQL database connectivity
Machine learning based COVID-19 study performance prediction
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Review of recent advances in non-invasive hemoglobin estimation
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
A Presentation on Artificial Intelligence
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Mobile App Security Testing_ A Comprehensive Guide.pdf
Empathic Computing: Creating Shared Understanding

The Connected Car UX Through APIs - Francois Lascelles, VP Solutions Architect, CA Layer 7 @ Telematics Detroit

  • 1. The connected car App experience Improving consumer adoption through secure APIs 6/4/2014 © 2014 CA. All rights reserved. Francois Lascelles VP Solutions Architecture, CA Technologies
  • 2. 2 © 2014 CA. ALL RIGHTS RESERVED. Mobile Car 3rd party service/soc ial Connected Car Service Provider How do you connect any of these things? The connected car Connected to what?  Manufacturer or service provider – Telemetry, call home  Entertainment platforms – E.g. Netflix  Weather, traffic info, gps  Social media  A mobile app used by driver
  • 3. 3 © 2014 CA. ALL RIGHTS RESERVED. Connections = APIs Web Web API  Presentation, interface  Information  Information Presentation, interface { “min”: “23C”, “max”: “11C”…}
  • 4. 4 © 2014 CA. ALL RIGHTS RESERVED. APIs connect everything { “min”: “23C”, “max”: “11C”…}
  • 5. 5 © 2014 CA. ALL RIGHTS RESERVED. Mobile Car 3rd party service/soc ial Connected Car Service Provider APIs of the connected car APIs APIs APIs App App App
  • 6. 6 © 2014 CA. ALL RIGHTS RESERVED. Connected car user experience In-car/IHU apps Emerging/immature app marketplace Closed ecosystem Mobile apps Mature app marketplace Rich experience
  • 7. 7 © 2014 CA. ALL RIGHTS RESERVED. Mobile Car 3rd party service/soc ial Connected Car Service Provider Companion app APIs APIs APIs { unlock} { unlock}
  • 8. 8 © 2014 CA. ALL RIGHTS RESERVED. Companion App
  • 9. 9 © 2014 CA. ALL RIGHTS RESERVED. Mobile Car 3rd party service/soc ial Connected Car Service Provider Mobile powered car sharing service APIs APIs APIs {book it} {pickup} {find it}
  • 10. 10 © 2014 CA. ALL RIGHTS RESERVED. Good UX -> good business UX Adoption
  • 11. 11 © 2014 CA. ALL RIGHTS RESERVED. Security matters too  Safety – When cars can be controlled remotely … “My car was hacked”  Privacy – Locate users – Abuse of driver history data APIs are becoming the attack vector of choice for the new generation of hackers
  • 12. 12 © 2014 CA. ALL RIGHTS RESERVED. UX Disruptors  Key defensive techniques, such as user authentication disrupt UX  The impact on user experience is more severe in mobile context  Compounding factors: – Challenge frequency – Number of secrets – Secret complexity
  • 13. 13 © 2014 CA. ALL RIGHTS RESERVED. Reconciling UX and Security Identify yourself Show me my data
  • 14. 14 © 2014 CA. ALL RIGHTS RESERVED. Public vs confidential apps  Public devices and public clients shift burden of authentication to a user (lowering UX) – Pattern: Secure API flows which assert registered device/client Mobile Connected Car Service Provider {prove possession} Register device, app In-car appHSM
  • 15. 15 © 2014 CA. ALL RIGHTS RESERVED. User-managed delegation  Users delegate applications to act on their behalf – Pattern: revocation should be as easy as delegation Connected Car Service Provider … later, device lost or stolen Connected Car Service Provider Revoke app, device Authorize app, device
  • 16. 16 © 2014 CA. ALL RIGHTS RESERVED. Risk and context-based authorization  Low – Must have valid session  Medium – Must have a ‘fresh’ session  High – Registered device only – Challenge user every x minutes Risk associated with API call  Multifactor – Infotainment + mobile
  • 17. 17 © 2014 CA. ALL RIGHTS RESERVED. API-enabled connected car service provider  Beyond enhancing the user experience, APIs enable new business and partnership  250M connected cars = big data – Telemetry history – APIs lets you monetize this information Driving new business models and partnerships Insurance Urban planning Emergency response Real-time traffic info  Connected car API infrastructure – Correlate – Anonymize – Secure [your idea here]
  • 18. 18 © 2014 CA. ALL RIGHTS RESERVED. API infrastructure for the connected car  Enable innovation Layer 7 API Management Solutions App developer services Internal/3rd party developer on boarding API discovery App registration API Key issuing Analytics Billing Mobile SDKs Runtime API services Secure API delivery Access control Enterprise integration Identity brokering Device registration Social/cloud integration Threat protection, sanitization  Deliver, scale and secure
  • 19. 19 © 2014 CA. ALL RIGHTS RESERVED. Thank you © 2014 CA. All rights reserved. Francois Lascelles VP Solutions Architecture, CA Technologies

Editor's Notes

  • #4: When we talk about APIs, we’re talking for example of Web apis. Web apis are different from the web … That’s how mobile apps are powered today Reproducing a web browsing experience on any device is not the path to optimal user experience The information needs to be consistent across devices, but native applications produce the best experiences Better user experience because not everything is a browser
  • #5: And of course by decoupling presentation from content, you make it easier to consume the content across platforms. This is what allows yahoo Weather to be on your fridge. Netflix became available everywhere because of APIs. This is a huge advantage for them. So APIs are a great way to more easily reach out to the audience to their platform of choice By extension, APIs enable this connected car concept. TEXT TO SPEECH AUGMENTED REALITY
  • #6: In the context of the connected car, where are the Apps and where are the APIs
  • #7: Publication “Apps for connected cars? Your mileage may vary” Quote “The connected car app ecosystem resembles mobile apps in 2008” A rich connected car user experience has to tie into the existing digital life of the user and therefore has to enable mobile apps The in-car app marketplace is still very fragmented and until we get a few standards in place that developers can rally around, the apps available in-car will continue to be limited
  • #8: With these APIs in place, connected car manufacturers can come up with great mobile apps for a vehicle owner to interact with its vehicle These apps provide functionality to lock/unlock, remote start, turn on horn and lights to make it easier to find the car in a parking lot How does this work though Well it’s not like the app on your mobile phone talks directly to your car This two-step interaction allows the connected car service provider to put additional checks in place
  • #9: Taken in parkinglot of temelatics 2014 first day
  • #10: A car sharing service manages a fleet of vehicles that it makes available to its members There is already an IoT aspect to this and cars are already connected to a central system so that the service provider can keep track of where the cars are at any time Because the user doesn’t own the car in this case, the mobile experience is that much more important The subscriber interacts with the service provider … The service provider has its own interactions with the car itself … where are you The experience is great. Imagine urban situation, parking is not an option Valet pickup experience once the cars start driving themselves
  • #11: Easy sells The better the experience, the better the adoption and more adoption generally translates into more business Good UX is sticky In the context of the connected car, good UX is about your car integrating within the digital lifestyle of the user Anecdote: no BT music streaming in your car is bad
  • #12: My car was hacked Imagine somebody being able to unlock your car with his smart phone Imagine somebody being able to remote shut down your car as you drive. Remote steer target down a cliff. In a future where cars are self-driven, the potential risks only go up
  • #13: The problem with security though is that it often gets in the way of UX
  • #14: The real challenge is to reconcile UX and security The winner here is the one who can make the experience seamless, transparent, with