Embedded engineering
Embedded Security Implementation for Production ECUs

At a glance
- Architecture
- Development
- Verification
- Production
- Standards referenced
- AUTOSARISO/SAE 21434ISO 26262
- Core deliverables
- Embedded security design
- Key management concept
- Configuration guidance for AUTOSAR security modules
- Hardening checklist per ECU class
The problem we are asked to solve
- Security requirements are written but not implementable on the target hardware.
- Key management is decided late and becomes a production constraint.
- Communication protection is inconsistent across buses and domains.
- Hardware security capabilities are underused.
What changes as a result
- Security controls implemented within real resource constraints
- Consistent cryptographic and key-handling approach across ECUs
- Protected in-vehicle communication where it matters
- Implementation evidence ready for verification
Scope of work
What the engagement covers
Scope is agreed per programme. These are the activities we most often deliver for this service.
- Secure boot and firmware integrity
- Hardware security module and hardware trust anchor usage
- Key management concept and lifecycle
- AUTOSAR Classic and Adaptive security configuration
- SecOC and communication protection
- Diagnostic and access control hardening
- Debug and production interface lockdown
- Secure coding and code review support
Engagement methodology
How we work
A predictable sequence, adapted to your process and release gates rather than replacing them.
- 01
Review target constraints
Understand the hardware trust anchors, resources, toolchain, and basic software already in place.
- 02
Design the security concept
Define secure boot, key handling, cryptographic services, and communication protection for the platform.
- 03
Support implementation
Work with the development team on configuration, integration, and secure coding for the chosen platform.
- 04
Review code and configuration
Inspect the implementation against the design and against known embedded failure patterns.
- 05
Support verification
Prepare the implementation for security testing and help close findings without destabilising the build.
Deliverables
Every engagement ends with artefacts your organisation owns and can defend in review.
- Embedded security design
- Key management concept
- Configuration guidance for AUTOSAR security modules
- Hardening checklist per ECU class
- Code and configuration review findings
- Implementation verification support
Relevant standards
We help organisations interpret and implement these requirements. We do not certify or approve organisations.
- AUTOSAR
- ISO/SAE 21434
- ISO 26262
Typical use cases
- Introducing secure boot on a new ECU generation
- Defining a key management concept across a platform
- Enabling SecOC on safety-relevant communication
- Locking down production and diagnostic interfaces
Evidence
Case studies covering Embedded Security and AUTOSAR work are being prepared for publication. Automotive security engagements are normally confidential, so we discuss comparable scope, method, and deliverables directly rather than publishing unverifiable claims.
Questions
Frequently asked
Do you support both AUTOSAR Classic and Adaptive?
Can you work with our existing supplier stack?
Related services
Often delivered together
Automotive Cybersecurity Engineering
Turn cybersecurity risk into traceable requirements, implementable controls, and verification-ready work products.
View serviceAutomotive Penetration Testing and Red Teaming
Adversary-led testing of ECUs, in-vehicle networks, wireless interfaces, applications, and supporting backends.
View serviceFunctional Safety
Coordinate safety and security engineering so the two disciplines strengthen rather than contradict each other.
View service
Discuss Your Cybersecurity Program
Tell us where the programme is today and we will outline a realistic next step.
