zk-ScalHard: PUF-Based ZKP for Scalable Secure OTA

Arxiv pdf 2026-07-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

Todays automotive industry is transitioning to a zonal-oriented architecture (ZoA) for software-defined vehicles (SDVs). This enables frequent, flexible software updates for 100+ electronic control units (ECUs) via over-the-air (OTA) updates. Although OTA updates improve vehicle efficiency and fix security bugs, they can also pose security risks that may lead to safety-critical issues. To provide secure OTA updates, current industry standards include the Uptane framework and the AUTOSAR adaptive platform. These solutions are based on public-key infrastructure (PKI). However, vehicle authentication during OTA updates creates a significant bandwidth bottleneck in in-vehicle (IV) and vehicle-to-cloud (V2I) communications as ECU density increases. It also exposes a vehicles sensitive configuration and passenger data. Furthermore, their centralised architecture creates a single point of failure. The new Zonal SDV requires decentralised, scalable vehicle authentication with data privacy. To address these issues, we propose zk-ScalHard, a scalable and privacy-preserving silicon-to-cloud authentication protocol. To design and implement zk-ScalHard, (1) we introduce a decentralised, hybrid, and hierarchical trustpromotion architecture model which utilises hardware-rooted silicon physical unclonable functions (PUFs). We design and code two zero-knowledge proof (ZKP) circuits: (2) zonal identity and integrity (ZIDI) and (3) high-performance computing aggregation (HPCA). These ZIDI and HPCA circuits employ multi-party computation (MPC) and recursive aggregation to achieve decentralisation and scalability, respectively. The integration of ZKPs and silicon PUFs ensures 100% vehiclelevel data sovereignty. We benchmark zk-ScalHard against the industry-standard Uptane framework. Evaluation results demonstrate that zk-ScalHard achieves constant O(1) communication and verification complexity, down from linear O(n). Further, it reduces authentication bandwidth and the temporal attack surface by 99.2% and 99.9%, respectively. These results demonstrate that zk-ScalHard provides a scalable, secure, and GDPR-compliant architecture for next-generation Zonal SDVs.

Loading executive summary...

LINK COPIED TO CLIPBOARD