Papers for

automotive network engineers

Papers whose findings have a practical use for this group, as judged from the abstract. Open a paper to read what it means in practice.

Automotive networks gain zero trust without extra infrastructure

Lightweight Zero Trust via Automotive SDN

Abstract: Zonal in-vehicle networks ship Ethernet, MACsec, and TSN, but treat the network itself as trusted: once configured at the factory, there is no standardized runtime way to easily revoke access, rotate keys, or contain a compromised ECU. Zero Trust Architecture targets exactly that gap, yet existing automotive ZTA proposals bolt on dedicated infrastructure that duplicates the SDN management plane already required to enable SDVs. Thus, ZTA is not yet adopted in the automotive domain, and the question remains: can we do better? We answer this in two steps. Step 1 analyses what Open Alliance TC17~v1.0 MACsec/MKA with pre-shared CAKs already provides in terms of NIST SP~800-207 ZTA tenets. Step 2 adds CORECONF/YANG management as proposed in Open Alliance TC19, maps the SDN Controller and Agents one-to-one onto NIST's PE, PA, and PEP. We then instantiate this with two YANG-based mechanisms: a network-access-control flow and a key-management scheme. The result fully covers five and two partially of the seven tenets with no ZTA-specific infrastructure added.

Wed 9 SeptCryptography and SecurityNetworking and Internet Architecture
The gist
Cars are getting smarter but their internal networks usually trust all components once set up, which can be risky if a part is hacked. The authors looked at existing automotive standards and combined them with network management methods to bring zero trust security principles to cars. This approach improves security by controlling access and managing keys without adding extra complicated hardware. It covers most important zero trust rules using what cars already have inside.
Open 2609.09817v1