
Foundational Standard for Automotive Key Management
Secure key management across the manufacturing process has become essential as global automotive cybersecurity regulations become mandatory.
Automotive key and policy management centrally controls the security key lifecycle and enables key injection into individual ECUs through End-of-Line (EOL) equipment. Connecting OEM and supplier systems is therefore critical to ensuring security across the manufacturing ecosystem.
AutoCrypt® KeyLink provides an end-to-end security workflow by connecting KeyLink-Server, the central management system, with KeyLink-Edge, deployed at production sites.
By enabling the issuance, injection, and control of security keys and policies throughout the vehicle lifecycle, AutoCrypt® KeyLink helps meet global security standards and improve production reliability.
/ Key Features
Middleware-based Management
Full Lifecycle Coverage
Flexible Integration
Integrity Verification
Minimizes physical changes to OEM servers and supplier production equipment through software-based integration.
Supports key management from generation to revocation, with tracking of key status and processing history.
Integrates with production equipment, KMS, PKI, and other external systems for flexible key management.
Verifies key injection integrity and records operation history for systematic traceability.
/ System Architecture
Secure Key Injection and Certificate Distribution Across the Vehicle Lifecycle
AutoCrypt® KeyLink is an integrated solution for issuing and managing security keys and policies throughout vehicle design, production, and operation. The system consists of KeyLink-Server for centralized management and KeyLink-Edge for production-site control.


/ Why AUTOCRYPT
KeyLink-Server
1. Middleware for OEM and Supplier Systems
Connects OEM PKI/KMS infrastructure with supplier production systems, integrating certificate requester verification (RA), key lifecycle management, firmware encryption/decryption, and signature verification into a unified process.

2. Flexible Security Policies and Algorithm Support
Manages security policies by project, vehicle model, and key purpose. Supports symmetric (AES, ARIA, SEED) and asymmetric (RSA, ECDSA, EdDSA) algorithms with various key lengths.

3. Master Key Control and Dervied Key Generation
Generates master and derived keys for ECUs and other target systems, with metadata management and tracking by project, supplier, and serial number.

4. Integrity Verification and Server Redundancy
Verifies production data through Message Authentication Code (MAC) and certificate-based signatures, while server redundancy protects key and certificate data and ensures production continuity.

KeyLink-Edge
1. TEE-Based Secure Key Storage and Exposure Prevention
Isolates and protects keys within an ASPICE CL2-certified Trusted Execution Environment (TEE), preventing exposure to the Rich Execution Environment (REE) through access controls and key identifier-based mechanisms.

2. Real-time Status Monitoring
Tracks key and certificate processes from generation to initial ECU injection, recording status, retries, and approvals to reduce production risks and ensure traceability.

3. Secure Firmware Integrity and Regulatory Compliance
Separates development and production keys and protects signing keys within the Trusted Execution Environment (TEE), supporting firmware integrity and compliance with ISO/SAE 21434, UN R155, and UN R156.

4. Firmware Signing History and Policy Customization
Tracks firmware signing history by ECU model and enables signing configurations based on OEM security policies and requirements.

/ Hardware Line-up


