Lightweight Zero Trust via Automotive SDN

📅 2026-09-09
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
论文针对车载网络信任问题,通过分析现有MACsec/MKA及引入CORECONF/YANG管理方案,提出了一种无需额外基础设施的轻量级零信任架构。
📝 Abstract
Zonal in-vehicle networks ship Ethernet, MACsec, and TSN, but treat the network itself as trusted: once configured at the factory, there is no standardized runtime way to easily revoke access, rotate keys, or contain a compromised ECU. Zero Trust Architecture targets exactly that gap, yet existing automotive ZTA proposals bolt on dedicated infrastructure that duplicates the SDN management plane already required to enable SDVs. Thus, ZTA is not yet adopted in the automotive domain, and the question remains: can we do better? We answer this in two steps. Step 1 analyses what Open Alliance TC17~v1.0 MACsec/MKA with pre-shared CAKs already provides in terms of NIST SP~800-207 ZTA tenets. Step 2 adds CORECONF/YANG management as proposed in Open Alliance TC19, maps the SDN Controller and Agents one-to-one onto NIST's PE, PA, and PEP. We then instantiate this with two YANG-based mechanisms: a network-access-control flow and a key-management scheme. The result fully covers five and two partially of the seven tenets with no ZTA-specific infrastructure added.
Problem

Research questions and friction points this paper is trying to address.

Zero Trust Architecture
Automotive SDN
MACsec
TSN
ECU
Innovation

Methods, ideas, or system contributions that make the work stand out.

Lightweight Zero Trust
Automotive SDN
MACsec/MKA
CORECONF/YANG
NIST SP 800-207
🔎 Similar Papers
No similar papers found.