Axowl.com
000
%

Self-driving firmware integrity. Anti-spoofing for V2X.

An autonomous vehicle is a 2-ton networked endpoint. A spoofed V2X message from a roadside attacker can force a phantom emergency brake; a tampered OTA update can disable the entire safety stack. DPSM seals each vehicle's identity in silicon and verifies every firmware image and every V2X packet against a multi-tier hardware quorum.

Where Autonomous Mobility (V2X) breaks today

V2X message spoofing

Roadside spoofers can broadcast false 'emergency brake' or 'green wave' messages. Vehicles acting on unauthenticated V2X can be weaponized.

UNECE R155 — now mandates cryptographic message authentication

OTA firmware compromise

An attacker who compromises a manufacturer's signing key can push malicious firmware to an entire fleet — a recall-class incident.

$1.4B — Toyota recall cost from a single firmware defect · 2023

ADAS calibration tampering

Service-bay attackers can subtly alter ADAS calibration to bias collision detection, with no on-vehicle audit trail.

ISO/SAE 21434 — requires per-component cybersecurity engineering

Three patents, deployed against this industry's threat model

Each of Axowl's three filed patents maps to a specific structural failure mode in Autonomous Mobility (V2X). Together they form a single, end-to-end defense.

Hierarchical Distributed Trust Fabric — Vehicle (L1) · Roadside Unit (L2) · Regional Cloud (L3)

Each vehicle's V2X module carries a PUF identity at L1. Roadside Units (RSUs) act as L2 verifiers, and the regional traffic-management cloud forms L3. A spoofed vehicle simply cannot enter the trust fabric — without a valid PUF, no signed message is accepted by either the RSU or neighboring vehicles.

Transition-Sealed Integrity System — Every OTA update, every safety-critical command, sealed

Each OTA image is sealed by the manufacturer's L1 device, re-sealed at the L2 distribution server, and verified at the vehicle. Every safety-critical actuation (steering, braking, ADAS engagement) is sealed for black-box reconstruction. Service-bay tampering on calibration is sealed and visible at next OTA check-in.

Pre-grant LLM Conflict Verification — Maintenance permission conflicts caught pre-grant

A technician permission such as "modify ADAS calibration + disable accident reporting" is identified by the LLM gate as a conflict-of-interest pattern and refused. Pre-commit blocking eliminates the "silent calibration shift" attack path before it can be issued.

Deployment that fits the threat model

Initial fleet deployments use the Defense tier with TPM-anchored vehicle ECUs. Production silicon integrates the PUF directly into the SoC for line-rate V2X verification at AWS F2-equivalent throughput on-vehicle.

Recommended tier: T2 · Defense → T3 · Iron via SoC

Deployment path: Vehicle SoC integration · RSU on F2 · Regional cloud on AWS Nitro

Operational detail: Roadside Units (RSUs) deploy on F2-class hardware within 72 hours. Vehicle-side integration begins with an MPW prototype, then transitions to volume ASIC via Korean foundry partners. Regional traffic-cloud verification runs on AWS Nitro Enclaves.

Three concrete deployments

Robotaxi command authentication

Every dispatch, every passenger pickup, every safety-stop command is sealed with a chain that begins at the operator's PUF and terminates at the vehicle's PUF.

OTA update verification

The vehicle refuses to flash any image whose seal chain does not terminate at the manufacturer's original PUF. Compromised distribution servers cannot inject malicious firmware.

V2X anti-spoofing

Roadside spoofers cannot impersonate a vehicle because they lack a valid PUF response. False emergency-brake propagation is structurally impossible.

Versus what's deployed today

Today — Per-OEM PKI

OEM signing keys are concentrated in HSMs at the manufacturer. A single compromise affects every vehicle that ever shipped with that key.

With DPSM — Axowl DPSM

Each vehicle holds its own PUF-derived identity. Even a full compromise of the OEM signing infrastructure cannot forge a signed command for any individual vehicle.

Standards & regulatory frameworks aligned

  • UNECE WP.29 R155 (CSMS)
  • UNECE R156 (SUMS · OTA)
  • ISO/SAE 21434
  • ISO 26262 ASIL-D
  • EU GSR 2
  • NHTSA Cybersecurity Best Practices