Solutions · Automotive & Connected Vehicles

PKI that ships with the car and lives 20 years.

Connected vehicles, V2X, and OTA updates need certificates that survive a two-decade lifecycle. TigerTrust delivers automotive-grade PKI aligned to ISO 21434, UNECE WP.29 R155/R156, IEEE 1609.2, and SAE J3101.

The problem

Every ECU is an attack surface. Every OTA is a supply chain.

A modern vehicle ships with 100+ ECUs, dozens of V2X pseudonymous certificates, and a 20-year OTA update window. Manual PKI processes designed for corporate laptops break the moment the first cellular gateway ships.

Without automotive PKI
  • Shared keys across ECUs mean one dumped firmware unlocks the fleet
  • V2X pseudonym rotation stalls without SCMS automation — vehicles fall out of trust
  • Unsigned or replay-vulnerable OTA updates risk bricking cars and safety recalls
  • Suppliers, OEMs, and dealers each keep their own key stores — no lineage, no audit
  • ISO 21434 and UNECE R155 findings block new-model type approval in the EU
With TigerTrust automotive PKI
  • Per-ECU identities issued from HSM-backed sub-CAs — no key sharing across the vehicle
  • IEEE 1609.2 / ETSI ITS SCMS with automated pseudonym rotation at scale
  • Signed OTA firmware with rollback protection and per-image verification
  • Full VIN-linked audit trail across supplier, OEM, and dealer boundaries
  • Reports mapped to ISO 21434 clauses and UNECE R155/R156 CSMS/SUMS controls
V2X SCMS

Pseudonym certificates at fleet scale

A complete Security Credential Management System for C-V2X: issue pseudonym batches, rotate on schedule, and revoke misbehaving devices without impacting the rest of the fleet.

How it works
  • IEEE 1609.2 and ETSI TS 102 941 certificate formats
  • Pseudonym batching with configurable rotation windows
  • Misbehaviour authority hooks for revocation input
  • Regional CA hierarchies for cross-border deployments
Connected vehicle communicating with roadside infrastructure
OTA updates

Signed firmware, rollback-protected

Every ECU image is signed by an HSM-backed key with per-target policies. Verified boot enforces version monotonicity so a rolled-back firmware cannot re-open a patched CVE.

How it works
  • Uptane-compatible signing workflow
  • Per-ECU code signing keys, no shared secrets
  • Rollback and downgrade protection built in
  • Air-gapped signing ceremony for root images
Firmware update rolling out to a connected fleet
ECU identity

Hardware-anchored ECU authentication

Each ECU gets a unique identity minted from its secure element or HSM. VIN-linked certificates flow from Tier-2 supplier through OEM assembly with a full chain of custody.

How it works
  • SAE J3101 hardware-protected key storage
  • VIN-bound leaf certificates
  • Supplier-to-OEM chain of custody
  • In-vehicle network authentication (CAN, Automotive Ethernet)
Automotive electronic control unit on a test bench
Lifecycle

20-year certificate lifecycle management

Vehicles outlive most PKI vendors. TigerTrust plans for algorithm agility, root ceremony rotation, and post-quantum migration across the vehicle service life.

How it works
  • Crypto-agile issuance (RSA, ECDSA, PQC-ready)
  • Scheduled root and sub-CA rotation without fleet disruption
  • Field re-issuance without dealer visit
  • Long-tail support for legacy protocols
Long-term fleet lifecycle management dashboard
Built for connected mobility

The automotive PKI stack, assembled.

From tier-supplier factory floors to the dealer bay and every kilometre on the road, one platform issues, monitors, and revokes.

V2X SCMS
IEEE 1609.2 pseudonym issuance and rotation at fleet scale.
  • ETSI ITS compatible
  • Pseudonym batching
  • Misbehaviour hooks
OTA code signing
HSM-backed signing for firmware and software updates.
  • Uptane-compatible
  • Per-target keys
  • Rollback protection
ISO 21434 evidence
Automated control mapping for automotive cybersecurity audits.
  • CSMS artefacts
  • SUMS artefacts
  • Type approval reports
ECU identity
VIN-bound certificates rooted in SAE J3101 hardware storage.
  • Per-ECU keys
  • HSM anchored
  • Supplier lineage
Fleet operations
Manage millions of vehicles from a single control plane.
  • Bulk provisioning
  • Regional CAs
  • Sub-minute revocation
Dealer & aftermarket
Field re-issuance and diagnostic access without shared keys.
  • Time-boxed access
  • Signed diagnostics
  • Audit trail

From production deployments

5M+
Vehicles under management
200M+
Certificates issued
20 yrs
Vehicle lifecycle supported
99.99%
Provisioning success rate
Case study
Tier-1 · Connected vehicle OEM

Zero cybersecurity findings at UNECE R155 type approval.

The auditor asked for CSMS evidence covering three model years. We generated the pack in minutes, mapped clause by clause. That used to be a six-week project.
Head of Vehicle Cybersecurity
3.2M
ECUs under management
0
R155 findings at approval
18 mo
Faster than legacy PKI plan
Integrations

Fits your existing stack

HSMs, secure elements, and toolchains the automotive supply chain already runs on.

Thales Luna
HSM
Entrust nShield
HSM
Utimaco CryptoServer
HSM
Infineon Aurix
Secure Element
NXP S32
Secure Element
Renesas RH850
ECU MCU
Uptane
OTA
AUTOSAR Adaptive
Runtime
ETSI ITS-G5
V2X
C-V2X 3GPP
V2X
Elektrobit tresos
Toolchain
Vector CANoe
Test tooling
FAQ

Frequently asked questions

ISO 21434 clauses 8 (risk assessment) and 10 (cybersecurity operations) are covered by the audit trail and continuous inventory. UNECE R155 CSMS obligations for identity, cryptographic controls, and incident response are backed by discovery, per-ECU issuance records, and revocation logs. Evidence packs export directly to your type-approval documentation with clause-level cross-references.
Yes. TigerTrust implements a full Security Credential Management System aligned to IEEE 1609.2 and ETSI TS 102 941. Pseudonym batches issue on your configured rotation window (typically 5 minutes with 20 concurrent certs per vehicle). Regional CA hierarchies support cross-border deployments and the Misbehaviour Authority hooks let you plug in your own reporting sources for revocation input.
TigerTrust integrates with Thales Luna, Entrust nShield, Utimaco, and AWS CloudHSM for image signing keys. Air-gapped signing ceremonies for root images use quorum control (M-of-N) with signed transcripts. Uptane-compatible signing workflows keep per-target and per-role key separation so a compromise of the image repository cannot forge signed updates.
Vehicles outlive most PKI vendors. TigerTrust plans for crypto-agility from day one: RSA, ECDSA, and PQC (ML-DSA, ML-KEM hybrid) issuance profiles per ECU class. Root and sub-CA rotation is scheduled — clients pick up new chains from OTA trust bundle updates. The 20-year horizon includes a documented migration path to NIST-selected post-quantum suites.
Every certificate carries a VIN-bound identity plus supplier lineage. Tier-2 suppliers provision from their own sub-CA under the OEM root; assembly plants attach the VIN linkage; dealers use time-boxed diagnostic credentials with full audit. The chain of custody survives every hand-off — auditors can walk the trail from silicon vendor to dealer bay in the dashboard.
Yes. SAE J3101 hardware-protected key storage backs identities for CAN authentication (SecOC) and Automotive Ethernet (MACsec, TLS 1.3 in AUTOSAR Adaptive). Per-ECU keys eliminate the shared-secret pattern; a dumped ECU cannot impersonate the rest of the network.

Ship connected vehicles the regulator trusts.