Key Management Infrastructure

AutoCrypt KeyLink

Proven Key Distribution Middleware

Foundational Standard for Automotive Key Management

Secure key management across the manufacturing process has become essential as global automotive cybersecurity regulations become mandatory. 

Automotive key and policy management centrally controls the security key lifecycle and enables key injection into individual ECUs through End-of-Line (EOL) equipment. Connecting OEM and supplier systems is therefore critical to ensuring security across the manufacturing ecosystem.

AutoCrypt® KeyLink provides an end-to-end security workflow by connecting KeyLink-Server, the central management system, with KeyLink-Edge, deployed at production sites. 

By enabling the issuance, injection, and control of security keys and policies throughout the vehicle lifecycle, AutoCrypt® KeyLink helps meet global security standards and improve production reliability.

/ Key Features

Middleware-based Management

Full Lifecycle Coverage

Flexible Integration

Integrity Verification

Minimizes physical changes to OEM servers and supplier production equipment through software-based integration.

Supports key management from generation to revocation, with tracking of key status and processing history.

Integrates with production equipment, KMS, PKI, and other external systems for flexible key management. 

Verifies key injection integrity and records operation history for systematic traceability.

/ System Architecture

Secure Key Injection and Certificate Distribution Across the Vehicle Lifecycle

AutoCrypt® KeyLink is an integrated solution for issuing and managing security keys and policies throughout vehicle design, production, and operation. The system consists of KeyLink-Server for centralized management and KeyLink-Edge for production-site control. 

/ Why AUTOCRYPT

KeyLink-Server

1. Middleware for OEM and Supplier Systems

Connects OEM PKI/KMS infrastructure with supplier production systems, integrating certificate requester verification (RA), key lifecycle management, firmware encryption/decryption, and signature verification into a unified process.

2. Flexible Security Policies and Algorithm Support

Manages security policies by project, vehicle model, and key purpose. Supports symmetric (AES, ARIA, SEED) and asymmetric (RSA, ECDSA, EdDSA) algorithms with various key lengths.

3. Master Key Control and Dervied Key Generation

Generates master and derived keys for ECUs and other target systems, with metadata management and tracking by project, supplier, and serial number.

4. Integrity Verification and Server Redundancy

Verifies production data through Message Authentication Code (MAC) and certificate-based signatures, while server redundancy protects key and certificate data and ensures production continuity.

KeyLink-Edge

1. TEE-Based Secure Key Storage and Exposure Prevention 

Isolates and protects keys within an ASPICE CL2-certified Trusted Execution Environment (TEE), preventing exposure to the Rich Execution Environment (REE) through access controls and key identifier-based mechanisms.

2. Real-time Status Monitoring 

Tracks key and certificate processes from generation to initial ECU injection, recording status, retries, and approvals to reduce production risks and ensure traceability.

3. Secure Firmware Integrity and Regulatory Compliance

Separates development and production keys and protects signing keys within the Trusted Execution Environment (TEE), supporting firmware integrity and compliance with ISO/SAE 21434, UN R155, and UN R156. 

 

4. Firmware Signing History and Policy Customization

Tracks firmware signing history by ECU model and enables signing configurations based on OEM security policies and requirements.

/ Hardware Line-up

KeyLink-Server & KMS
KeyLink-Edge

Related Resources

AUTOCRYPT
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.