Designing a Zero-Trust Intrafamily PKI Framework for Multi-ECU IoT Ecosystems using example of Fuel Dispensing Units
编号:95 访问权限:仅限参会人 更新:2026-07-27 15:48:06 浏览:26次 Online

报告开始:2026年07月30日 15:10(Asia/Kolkata)

报告时间:15min

所在会场:[S2] Internet of Things & Network Slicing [S2-2] Internet of Things & Network Slicing

演示文件

提示:该报告下的文件权限为仅限参会人,您尚未登录,暂时无法查看。

摘要

Modern Internet of Things (IoT) ecosystems, including automotive systems, smart televisions, medical devices, and industrial Fuel Dispensing Units (FDUs), rely on interconnected Electronic Control Units (ECUs) and peripheral microcontrollers.

These devices handle critical operations but feature vulnerable firmware, flash memory components, and unencrypted bus topologies. Compromising a single node can allow an attacker to pivot through the entire internal network, resulting in unauthorized data access, code injection, or physical failure.

To address these vulnerabilities, this paper introduces a zero-trust, closed-user-group (CUG) Public Key Infrastructure (PKI) tailored for multi-ECU embedded deployments. Our architecture treats an interconnected group of peripheral IoT microcontrollers and a central host processing unit as a self-contained "family." Mutual authentication is enforced at system boot and at periodic operational run-time intervals.

The framework utilizes a dedicated manufacturing provisioning system that employs hardware-secured Root Certificate Authorities (CAs) and specialized physical testing jigs to write cryptographic credentials directly to non-volatile flash memory during assembly. At runtime, node integrity is verified using a hybrid cryptographic workflow combining Advanced Encryption Standard (AES-256) symmetric encryption with Secure Hash Algorithm 2 (SHA-256) digital signatures.

To validate the security posture of this ecosystem, we present a multi-layered audit methodology covering the provisioning process, cryptographic data-flow verification, and physical CA infrastructure security. Experimental results show that the entire mutual authentication loop for a standard multi-node FDU deployment finish well within a strict 500-microsecond threshold. This demonstrates that the proposed zero-trust framework provides strong protection against Man-in-the-Middle (MITM) attacks, firmware tampering, and unauthorized node replacements without degrading real-time performance.
 

关键词
PKI;IOT Security;Cyber Security;Zero-Trust;Fuel Dispensing Unit;driver-less vehicles;UAV Security;Satellite Security;Hack-proof;CCTV;MITM
报告人
Rakesh Mohan Goyal
CEO Sysman Computers

Dr. Rakesh Mohan Goyal is perpetual student of Information Security and some more subjects.

He is the Director of Sysman Computers, Mumbai (www.sysman.in), a CERT-In and CCA empanelled cyber security audit organisation; and Director-General of Centre for Research & Prevention of Computer Crimes, India (CRPCC).

He is engaged in Cyber Security, IS Audit, Privacy and Cyber Forensics since 1991.

He has authored 6 books, first one titled “Computer Crimes” was published in 1993. He has also authored over 50 papers/articles on IT Security, some of these are discussed in national/international conferences. He has 6 patents / copyright in his name.

In his 53 years of career, he has done over 6000 IT Security assignments including Audit, GRC, Consulting and Forensics assignments, 150 software projects assignments and created two large software products.

He had been involved in some critical cyber security problem solving scenarios with out-of-the-box approach.

He is PhD in Cyber Security; PGDM from IIM-Bengaluru with Gold Medal; AMIE with Gold Medal and holds CISA, CISM, CMC, CCCI, CFE, FIE and few more certifications.

He is currently working on Project Triveni, a synergy among AI, Security and Cloud to auto-eliminate vulnerabilities in web-applications.

He also holds a First Degree Black Belt in Karate, Diploma in Acupressure Therapy and Certified as Trained Yoga

Vishal Gudhka
Senior Network Architect Versa Networks, Santa Clara, CA

I design and deliver next-generation networking and security architectures that enable organizations to operate securely, intelligently, and at a global scale. With over 14 years of experience across IOT, telecommunications, cloud, enterprise, and service provider environments, I focus on transforming legacy infrastructure into agile, software-driven, and security-first platforms. As a Senior Network Architect at Versa Networks, I lead strategic engagements for large enterprises and service providers, guiding the architecture and execution of advanced SD-WAN and SASE deployments. My work has driven large-scale modernization programs that strengthened security posture, improved multi-cloud application performance, and reduced operational complexity and cost. I am particularly focused on applying automation, intelligent traffic engineering, and integrated security to build resilient, self-optimizing networks.
 

稿件作者
Dr Rakesh Goyal Sysman Computers
发表评论
验证码 看不清楚,更换一张
全部评论
重要日期
  • 会议日期

    07月30日

    2026

    08月01日

    2026

  • 07月28日 2026

    注册截止日期

  • 07月30日 2026

    初稿截稿日期

主办单位
The United Societies of Science
承办单位
Kongunadu College of Engineering and Technology
协办单位
IEEE Section
IEEE Madras Section
历届会议
移动端
在手机上打开
小程序
打开微信小程序
客服
扫码或点此咨询