Abstract: A rigorous analysis of hybrid lattice-based cryptography applied to the Uptane security framework, demonstrating sub-2 ms signature verification on automotive gateways and resilience against harvest-now-decrypt-later attacks.
Traditional software update solutions rely on a single signing key. Uptane separates the Director repository (which specifies which ECUs should install which versions) from the Image repository (which holds the cryptographically signed binaries). Even if an attacker gains full control of the OEM cloud deployment server, they cannot push malicious firmware without the offline Image keys.