arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

zk-ScalHard:用于区域软件定义车辆中安全空中下载更新的可扩展且基于硬件的隐私保护认证

zk-ScalHard: Scalable and Hardware-Rooted Privacy-Preserving Authentication for Secure OTA Updates in Zonal SDVs

Shrikant Tangade, Bansi Pambhar, Valeria Loscri, Mauro Conti

arXiv 2607.07371首次发表:更新:

AI 中文总结

针对区域软件定义车辆OTA更新的安全认证问题,提出zk-ScalHard协议,利用硅PUF和两个ZKP电路构建分散分层信任提升模型,采用MPC和递归聚合实现分散可扩展,相比现有系统有显著改进,为未来车辆提供合规安全架构。

AI 中文摘要

汽车行业正在向面向区域的软件定义车辆(SDV)架构过渡,实现100多个电子控制单元(ECU)的频繁空中下载(OTA)更新。虽然OTA更新提高了效率,但引入了安全关键的安全风险。当前标准如Uptane和AUTOSAR Adaptive依赖公钥基础设施(PKI),随着ECU密度增加,基于PKI的认证会造成车载和车云通信带宽瓶颈,还因集中架构有暴露敏感车辆配置和乘客隐私风险。下一代区域SDV需要分散、可扩展且有数据隐私的认证。为此提出zk-ScalHard,一种基于硬件的隐私保护认证协议。引入利用硅物理不可克隆函数(PUF)和两个新颖零知识证明(ZKP)电路的分散分层信任提升模型,电路采用多方计算(MPC)和递归聚合实现分散和可扩展性。ZKPs和PUF的集成确保100%车辆级数据主权。与Uptane相比,zk-ScalHard实现恒定O(1)通信和验证复杂度,评估显示认证带宽减少99.2%,时间攻击面减少99.9%,为未来区域SDV提供了可扩展、安全且符合GDPR的架构。

英文摘要

The automotive industry is transitioning to Zonal-oriented Architectures (ZoA) for Software-Defined Vehicles (SDVs), enabling frequent over-the-air (OTA) updates for 100+ Electronic Control Units (ECUs). While OTA updates improve efficiency, they introduce safety-critical security risks. Current standards like Uptane and AUTOSAR Adaptive rely on Public-Key Infrastructure (PKI). However, PKI-based authentication creates bandwidth bottlenecks in in-vehicle and vehicle-to-cloud (V2I) communication as ECU density increases. It also risks exposing sensitive vehicle configurations and passenger privacy due to centralized architectures. Next-generation Zonal SDVs require decentralized, scalable authentication with data privacy. To address this, we propose zk-ScalHard, a hardware-rooted, privacy-preserving authentication protocol. We introduce a decentralized, hierarchical trust-promotion model utilizing Silicon Physical Unclonable Functions (PUFs) and two novel Zero-Knowledge Proof (ZKP) circuits: (1) Zonal Identity and Integrity (ZIDI) and (2) High-Performance Computing Aggregation (HPCA). These circuits employ multi-party computation (MPC) and recursive aggregation to achieve decentralization and scalability. The integration of ZKPs and PUFs ensures 100% vehicle-level data sovereignty. Benchmarked against Uptane, zk-ScalHard achieves constant O(1) communication and verification complexity, improving upon the linear O(n) complexity of current systems. Evaluation shows a 99.2% reduction in authentication bandwidth and a 99.9% reduction in the temporal attack surface. Our results demonstrate that zk-ScalHard provides a scalable, secure, and GDPR-compliant architecture for future Zonal SDVs.

CommentsOfficial Technical Report (v2 updated with official repository and implementation details). Produced in collaboration with the SERENDIPITY Team (Inria), the autoMoTIVe-X Lab, and the University of Padua. Source code and implementation: https://github.com/autoMoTIVe-X/zk-ScalHard

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑