发表机构
Robert Bosch GmbH; ETAS GmbH(罗伯特·博世有限公司; ETAS有限公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对车载网络缺乏运行时访问撤销与密钥轮换的问题,本文利用现有MACsec/MKA和CORECONF/YANG管理,将SDN控制器映射到NIST零信任组件,实现轻量级ZTA,覆盖七项原则中的五项。
AI 中文摘要
分区车载网络配备以太网、MACsec和TSN,但将网络本身视为可信:一旦在工厂配置完成,就没有标准化的运行时方法来轻松撤销访问、轮换密钥或遏制受损的ECU。零信任架构正是针对这一缺口,但现有的汽车ZTA方案附加了专用基础设施,重复了实现SDV所需的SDN管理平面。因此,ZTA尚未在汽车领域得到采用,问题依然存在:我们能做得更好吗?我们分两步回答。第一步分析Open Alliance TC17~v1.0 MACsec/MKA与预共享CAK在NIST SP~800-207 ZTA原则方面已提供的内容。第二步添加Open Alliance TC19中提出的CORECONF/YANG管理,将SDN控制器和代理一对一映射到NIST的PE、PA和PEP。然后,我们通过两种基于YANG的机制实例化此方案:一种网络访问控制流程和一种密钥管理方案。结果完全覆盖了七项原则中的五项,部分覆盖两项,且未添加任何ZTA专用基础设施。
英文摘要
Zonal in-vehicle networks ship Ethernet, MACsec, and TSN, but treat the network itself as trusted: once configured at the factory, there is no standardized runtime way to easily revoke access, rotate keys, or contain a compromised ECU. Zero Trust Architecture targets exactly that gap, yet existing automotive ZTA proposals bolt on dedicated infrastructure that duplicates the SDN management plane already required to enable SDVs. Thus, ZTA is not yet adopted in the automotive domain, and the question remains: can we do better? We answer this in two steps. Step 1 analyses what Open Alliance TC17~v1.0 MACsec/MKA with pre-shared CAKs already provides in terms of NIST SP~800-207 ZTA tenets. Step 2 adds CORECONF/YANG management as proposed in Open Alliance TC19, maps the SDN Controller and Agents one-to-one onto NIST's PE, PA, and PEP. We then instantiate this with two YANG-based mechanisms: a network-access-control flow and a key-management scheme. The result fully covers five and two partially of the seven tenets with no ZTA-specific infrastructure added.