Skip to main content
Hands-on lab
Secure Developer
Leader

AutoSec Crypto Lab

Key management that survives production

Design and operate automotive key hierarchies — provisioning, rotation, storage and revocation — across the vehicle and the backend that supports it.

Primary objectives

  1. Design a production key hierarchy
  2. Provision keys securely at end of line
  3. Operate certificate lifecycles for V2X and OTA
  4. Analyse cryptographic misuse in real firmware

Overview

What This Lab Is For

Key management is where otherwise sound cryptographic designs fail. The Crypto Lab covers the full lifecycle — hierarchy design, secure provisioning at end of line, certificate operations for OTA and V2X, rotation and revocation — and includes a firmware analysis exercise that shows what misuse actually looks like in shipped code.

Design and operate automotive key hierarchies — provisioning, rotation, storage and revocation — across the vehicle and the backend that supports it.

Learning goals

  • Specify a key management concept that passes assessment
  • Detect cryptographic weaknesses before they reach production

Technology stack

  • PKI
  • AES
  • ECC
  • HSM
  • TLS

Tools used

Hardware, Software and Security Tooling

Production-representative equipment and the toolchains engineers use on the job — not simulators standing in for them.

  • Hardware

    Physical targets and instrumentation you will work on directly.

    • HSM-equipped evaluation boardHSM
    • End-of-line provisioning rigSimulated production key injection environment
    • Firmware analysis workstationRig
  • Security tools

    Analysis, testing and cryptographic tooling applied to the targets.

    • Key management workbench
    • PKI simulation environment
    • Firmware crypto analyser

Exercises

2 Assessed Exercises

Each exercise is assessed rather than demonstrated. Durations are indicative and vary with cohort experience.

  1. End-to-end key hierarchy

    advanced

    Model provisioning, rotation and revocation across supplier and OEM boundaries.

    Duration
    4 hours
  2. Cryptographic misuse hunt

    intermediate

    Identify weak modes, hardcoded keys and entropy failures in ECU firmware.

    Duration
    3 hours

Learning outcomes

What You Can Demonstrate Afterwards

An at-a-glance summary — each item is expanded in the sections above and below.

Skills acquired

2

Assessed competencies, listed in full under Overview above.

Capability levels
L3 · Secure DeveloperL6 · Leader
Programs supported

3

Listed with their capability level in the next section.

Capability framework

Where This Lab Sits in the Framework

All six levels, and this lab’s relationship to each — including the ones it deliberately does not cover.

  1. Not covered

    Level 1 · Awareness

    Cybersecurity Awareness

    Covered by other labs in the estate

  2. Not covered

    Level 2 · Compliance

    Compliance Practitioner

    Covered by other labs in the estate

  3. Supported

    Level 3 · Secure Developer

    Build secure ECU software, crypto stack integration, SecOC, Secure Boot and HSM skills.

  4. Not covered

    Level 4 · Validation

    Security Validation Specialist

    Covered by other labs in the estate

  5. Not covered

    Level 5 · Offensive

    Offensive Security Expert

    Covered by other labs in the estate

  6. Supported

    Level 6 · Leader

    Lead CSMS transformation, security governance and enterprise capability programmes.

Common questions

AutoSec Crypto Lab FAQ

What engineers and their managers ask before booking lab time.

How much cryptography do I need to know already?
Enough to know what AES and ECC are for. The lab is about key management rather than primitive design — how keys are created, injected, separated by purpose, rotated and revoked across a fleet with a fifteen-year service life.
Does the lab cover post-quantum considerations?
It covers them as a planning problem rather than an implementation one: what a fifteen-year vehicle lifetime implies for algorithm agility, and how a key hierarchy should be structured so migration is possible at all.
What is the firmware misuse exercise?
You analyse real ECU firmware images for weak modes, hardcoded keys and entropy failures. It is consistently the exercise that changes how participants review their own code afterwards.

Get Your Engineers Into the AutoSec Crypto Lab

Lab access is included with the programs above, and can be delivered onsite, remotely or as part of a corporate academy.