The OBU is an endpoint on a public network. ShieldSync treats it like one.
Malware and intrusion detection, integrity monitoring and port control running inside the on-board unit — monitored from a cloud console, and still protecting the vehicle when it drops off the network.
Where it can run.
Every module in the vehicle layer depends on the connection. The connection is also the exposure.
A connected OBU runs a Linux or Android operating system, holds video and passenger data, accepts over-the-air updates, exposes USB and diagnostic ports in an unattended vehicle, and on electric vehicles sits alongside the CAN bus. That is the description of an endpoint, and endpoints are managed.
It is a general-purpose computer
An operating system, a filesystem, a network stack and an update mechanism — the same components that are protected everywhere else they appear, sitting in a bus at a depot overnight.
It holds data worth reaching
Video, passenger counts, ticketing events and position history. Some of it is evidence, and evidence is only useful if it can be shown not to have been altered.
It is physically accessible
USB and diagnostic ports in an unattended vehicle are the shortest path in, and they do not require a network at all.
What runs on the unit, and what you see of it.
On-device protection
Malware and intrusion detection, application whitelisting, and quarantine of unauthorised processes — running locally inside the OBU rather than inferred from traffic elsewhere.
Integrity monitoring
Continuous verification of firmware, binaries and configuration against signed baselines. An unauthorised change raises an alert instead of persisting quietly.
Port and interface control
USB, debug and diagnostic port policy enforcement — the most common physical attack path on an unattended vehicle.
Network anomaly detection
Unexpected outbound connections, command-and-control traffic patterns, and anomalous data volumes.
Offline operation
Full protection without connectivity. Events are buffered on the device and synchronised on reconnection, so a vehicle out of coverage is not a vehicle out of cover.
Cloud console
Fleet-wide threat dashboard, per-vehicle security posture, alerting and escalation, and an audit-ready incident history.
The evidence an IT review asks for.
IT security reviews
A named control on the vehicle endpoint, with a console that can show its state, rather than an assurance that the device is behind a firewall somewhere.
MeitY-aligned control expectations
Endpoint protection, integrity verification and logged incident history map onto the control families a public-sector security review works through.
Operator and city-authority audits
An incident history that can be produced on request, per vehicle and per fleet, with the dates and the disposition attached.
The rest of the vehicle layer.
OBU Software Stack
The on-board layer that hosts ShieldSync — and the first of the two ways it can run.
OBU to Cloud
How the events it raises are ingested, reconciled and stored with everything else the vehicle sends.
Security
The platform-side controls — and what covers a vehicle whose OBU will not host an agent.
Tell us the make and model.
Feasibility is a per-device question and we would rather answer it before you buy than after. Send the device list and we will come back with which units can host it.