Ilmu Komputer & AI editorial
Open AccessOA2026
Lightweight Zero Trust via Automotive SDN
Achieving NIST SP 800-207 tenets in zonal in-vehicle networks using Open Alliance TC17 MACsec/MKA and TC19 CORECONF/YANG without dedicated ZTA infrastructure
Friedrich Wiemer; Florian Wagnerยท 2026ยท DOI 10.48550/arXiv.2609.09817
The core problem
Zonal in-vehicle networks are increasingly adopting Ethernet, MACsec, and TSN to support software-defined vehicles (SDVs). However, these networks typically treat the network itself as trusted: once configured at the factory, there is no standardized runtime mechanism to revoke access, rotate keys, or contain a compromised Electronic Control Unit (ECU). Zero Trust Architecture (ZTA) directly addresses this gap by enforcing continuous verification and least-privilege access. Yet existing automotive ZTA proposals often require dedicated infrastructure that duplicates the SDN management plane already necessary for SDVs, hindering adoption. This work asks: can we do better? The authors propose a two-step approach: first, analyze what Open Alliance TC17 v1.0 MACsec/MKA with pre-shared CAKs already provides in terms of NIST SP 800-207 ZTA tenets; second, add CORECONF/YANG management as proposed in Open Alliance TC19, mapping the SDN Controller and Agents one-to-one onto NIST's Policy Engine (PE), Policy Administrator (PA), and Policy Enforcement Point (PEP). The result is instantiated with two YANG-based mechanisms: a network-access-control flow and a key-management scheme, achieving ful
Innovation
The analysis reveals that the combination of TC17 MACsec/MKA and TC19 CORECONF/YANG fully satisfies five of the seven NIST SP 800-207 ZTA tenets and partially satisfies the remaining two, without introducing any ZTA-specific infrastructure. Specifically, the tenets covered fully include: (1) all data sources and computing services are considered resources; (2) all communication is secured regardless of network location; (3) access to individual enterprise resources is granted on a per-session basis; (4) access to resources is determined by dynamic policy; and (5) the enterprise monitors and measures the integrity and security posture of all owned and associated assets. The partially covered tenets are: (6) the enterprise collects as much information as possible about the current state of network infrastructure and communications and uses it to improve its security posture; and (7) the enterprise requires all owned and associated devices to meet baseline security requirements. The partial coverage stems from limitations in runtime monitoring and baseline enforcement, which could be addressed with additional mechanisms. The key-management scheme successfully enables key rotation and
Zonal in-vehicle networks are increasingly adopting Ethernet, MACsec, and TSN to support software-defined vehicles (SDVs). However, these networks typically treat the network itself as trusted: once configured at the factory, there is no standardized runtime mechanism to revoke access, rotate keys, or contain a compromised Electronic Control Unit (ECU). Zero Trust Architecture (ZTA) directly addresses this gap by enforcing continuous verification and least-privilege access. Yet existing automotive ZTA proposals often require dedicated infrastructure that duplicates the SDN management plane already necessary for SDVs, hindering adoption. This work asks: can we do better? The authors propose a two-step approach: first, analyze what Open Alliance TC17 v1.0 MACsec/MKA with pre-shared CAKs already provides in terms of NIST SP 800-207 ZTA tenets; second, add CORECONF/YANG management as proposed in Open Alliance TC19, mapping the SDN Controller and Agents one-to-one onto NIST's Policy Engine (PE), Policy Administrator (PA), and Policy Enforcement Point (PEP). The result is instantiated with two YANG-based mechanisms: a network-access-control flow and a key-management scheme, achieving full coverage of five and partial coverage of two of the seven ZTA tenets without adding ZTA-specific infrastructure.
The methodology follows a systematic mapping of existing automotive networking standards to ZTA principles. Step 1 involves a detailed analysis of Open Alliance TC17 v1.0 MACsec/MKA with pre-shared Connectivity Association Keys (CAKs). The authors evaluate how these mechanisms align with the seven tenets of NIST SP 800-207. Step 2 introduces CORECONF/YANG management as specified in Open Alliance TC19, which provides a standardized way to manage network devices. The SDN Controller is mapped to NIST's Policy Engine (PE) and Policy Administrator (PA), while SDN Agents correspond to Policy Enforcement Points (PEP). This mapping enables dynamic policy enforcement and key management. Two YANG-based mechanisms are then instantiated: (1) a network-access-control flow that defines which ECUs can communicate and under what conditions, and (2) a key-management scheme that handles key rotation and revocation. The evaluation assesses coverage of the seven ZTA tenets. The architecture can be represented as follows:
Why it matters
The proposed approach demonstrates that ZTA can be achieved in automotive networks by leveraging existing standards, avoiding the overhead of dedicated ZTA infrastructure. This is significant because it reduces complexity and cost, potentially accelerating ZTA adoption in the automotive domain. The mapping of SDN components to NIST's PE, PA, and PEP provides a clear architectural blueprint. However, the partial coverage of tenets 6 and 7 indicates areas for future work: enhanced runtime monitoring and automated baseline enforcement. The use of CORECONF/YANG ensures interoperability and standardized management, which is crucial for multi-vendor environments. The authors note that the solution is lightweight, as it does not require additional hardware or software beyond what is already needed for SDVs. Limitations include the reliance on pre-shared CAKs, which may not be suitable for all deployment scenarios; future work could explore dynamic key establishment. Overall, this work answers the research question affirmatively: we can do better by reusing existing SDN and security mechanisms to implement ZTA in automotive networks. The implications extend to other domains with similar constraints, such as industrial IoT.
Who should read this
CS practitioners and researchers
Opening member contentโฆ