← Industries
SDV & IoT

Cybersecurity for fleets measured in decades.

A vehicle ships once and lives twenty years — through OTA updates, ownership changes, and the arrival of quantum computers. SCSA seals firmware to the ECU that runs it, gates every update on attested hardware, and can revoke a compromised unit fleet-wide with a signed, provable kill — cybersecurity that regulators can verify, not just audit.

A software-defined vehicle is a rolling datacenter with a twenty-year support contract and a physical attacker in the driver's seat. Every OTA update is a supply-chain event across millions of units; every ECU is a device someone can bench-probe; every telematics stream is data leaving hardware you no longer control. UNECE R155/R156 and ISO/SAE 21434 now make the OEM accountable for all of it — for the life of the fleet — and harvest-now, decrypt-later is not hypothetical when the vehicle outlives the cryptography it shipped with.

SCSA binds the software to the silicon. Firmware and models seal to the measured identity of the target ECU, so an update image lifted off the wire — or a unit lifted off the bench — yields ciphertext. Updates release only to hardware that attests, under quorum approval for safety-critical components, with every install and every refusal signed into a tamper-evident chain that maps directly onto R156 software-update evidence. A compromised unit or a stolen device is revoked with a fleet-wide signed kill command that produces destruction receipts — provable, not just asserted. And because the stack signs with post-quantum hybrids, the update channel a vehicle trusts in 2046 is the one you shipped in 2026.

01

Sealed OTA updates, attested installs

Update images decrypt only inside the measured target ECU. Installs are gated on attestation — with quorum approval for safety-critical components — and every install or refusal is a signed audit event mapped to R155/R156 evidence.

02

Fleet-wide revocation with proof

One signed command revokes a compromised unit's keys across the fleet, and each destruction returns a signed receipt. Stolen hardware goes dark provably, not hopefully.

03

Cryptography that outlives the vehicle

Post-quantum hybrid signing and key establishment (FIPS 203/204/205) protect a two-decade service life against harvest-now, decrypt-later collection — sign once, valid for the fleet's whole lifetime.

The vehicle outlives its threat model. Seal the software to the silicon and the guarantee rides along.