___vector-cybersecurity-application-area.9504707385646390381.png

Security Manager

Testing of Security-Protected ECUs and Networks.

Access secured vehicle communication without added complexity. The Security Manager connects Vector tools with OEM-specific security implementations through one consistent interface. 

Test, simulate and validate ECUs across OEMs and security concepts using the same workflow. Add-ons handle OEM-specific security functions in the background, while security-related operations and results are provided directly to your tools. Learn it once. Use it everywhere. Accelerate your development.

The Principle of the Security Manager...

...with and without access to OEM-specific backends.

Advantages

  • Create once. Use everywhere. Reuse the same security profiles across Vector tools and accelerate your workflow.
  • Built for OEM-specific requirements. Security Add-ons handle OEM-specific configurations, algorithms and backend integrations.
  • One interface. Consistent security. A central interface provides uniform access to security functions across all Vector tools while managing implementation details in the background.

Our Services

Secure Onboard Communication (SecOC)

SecOC authenticates communication between ECUs using Message Authentication Codes (MACs). Simulation and test tools communicate with ECUs only when the MAC is valid. For Vector tools, the Security Manager and OEM Security Add-ons* generate and validate the required MACs. The Security Manager securely stores the necessary inputs, including secret keys and freshness values, giving you a reliable foundation for secure testing and validation

(*) OEM Security Add-ons are available free of charge for selected OEMs. They contain OEM-specific security algorithms and processes, making standard security functions easier to use by handling OEM-specific behavior in the add-ons.

Secure Diagnostics Through Authentication

Only trusted testers gain access to diagnostic services. After successful authentication, the Security Manager unlocks diagnostic functions and critical operations such as flashing and variant coding. Together with the corresponding OEM Security Add-ons, it executes the required security processes seamlessly and reliably.

Transport Layer Security (TLS/DTLS)

TLS secures client-server communication over TCP and UDP. The Security Manager provides the TLS stack for Ethernet communication, making it easy to test TLS-secured applications and configure the required parameters.

Configure certificate hierarchies and define the required cipher suites. They determine the algorithms and parameters used to establish a secure data connection, ensuring reliable protection and efficient validation.

Internet Protocol Security (IPsec)

IPsec secures communication at the IP layer, protecting confidentiality, authenticity and integrity. This creates transparent security for higher-level protocols such as SOME/IP, DoIP, TLS and HTTP.

The Security Manager provides an IPsec stack with key protocol functions, including Authentication Header (AH) protection and IKEv2-based key exchange for certificate-based sessions. It also simplifies configuration through security profiles that bundle cipher suites, certificates and security policies. Existing StrongSwan configurations can be adopted directly to accelerate IPsec VPN setup.

Media Access Control Security (MACsec)

MACsec (Media Access Control Security) is used for authentication and encryption of data packets between two network nodes. The IEEE 802.1AE defines the protocol for securing the Ethernet link with all layers above.

The Security Manager provides software-based implementations of:

  • MACsec (IEEE 802.1AE-2018) for secure Ethernet communication.
  • MACsec Key Agreement (MKA) protocol (IEEE 802.1X-2020) for secure key management and connection setup.

The solution supports one ECU per Ethernet network in remaining bus simulations. Hardware-based MACsec support is planned for future releases.

A dedicated MACsec security profile bundles all parameters required to establish a MACsec connection, ensuring consistent configuration across software- and hardware-based environments.

Would you like to know how easy it is to test MACsec-secured communication? In this tutorial video Julia shows the test setup of CANoe with the Security Manager and a VN5620 interface. She also explains the configurartion of the parameters.

V2X Secure Communication

Manage V2X PKIs with ease. The Security Manager supports certificates for Europe (ETSI 103 097), the USA (IEEE 1609.2) and China (YD/T 3957-2021) in a single profile.

  • Flexible certificate management: Create, import and export certificates, including certificates for error and validation scenarios. 
  • Direct ECTL integration: Retrieve and import the latest certificates from the European Certificate Trust List online. 
  • Seamless CANoe integration: Use certificates directly in CANoe to generate security headers for V2X application messages

     

This gives you a consistent workflow for testing, simulation and validation of secure V2X communication. 

Management and Configuration of Security Parameters

Manage security parameters in one place. The Security Manager uses profiles to configure security services and algorithms consistently across your workflow.

  • Flexible key management: Import symmetric keys directly, in containers or in OEM-specific formats.
  • Centralized certificate management: Manage certificate hierarchies in PKI profiles and import certificates for TLS and diagnostic applications.
  • Seamless backend integration: Many OEMs store certificates in secure backends instead of sharing them directly. The Security Manager handles the communication in the background and provides certificate-based functions to your tools when needed.

     

The result: less complexity, consistent configuration and faster access to security services.

Overview of Related Vector Products

Get More Information