Skip to content
AutoST by Zyberum GmbH
Menu

Engine · SecurityAccess

Does your seed/key actually hold?

SecurityAccess (0x27) is what stands between an attacker and the dangerous services. AutoST checks whether that gate is real: random seeds, a strong key algorithm, a working lockout and an enforced sequence.

AutoST SecurityAccess analysis listing seed randomness, key algorithm, lockout and sequence findings

In short

The SecurityAccess engine actively tests UDS service 0x27. It measures seed randomness (constant, zero, low-entropy or incrementing seeds), attempts to recover the seed-to-key algorithm and tries a catalogue of default keys, checks whether a brute-force lockout triggers after wrong keys, and verifies that the ECU enforces the request-seed-then-send-key sequence. An opt-in ECU-reset probe checks whether the seed is predictable across reboots. Every probe is bounded and non-destructive by default; the reset probe is gated behind a confirmation.

What it checks

Five ways a seed/key gate fails

Seed randomness

Flags constant, zero, low-entropy or incrementing seeds, measured over multiple requests.

Key algorithm

Attempts to recover a weak seed-to-key relationship and tries a catalogue of known default keys.

Brute-force lockout

Checks whether the ECU locks out after repeated wrong keys, or lets an attacker keep trying.

Sequence enforcement

Verifies the ECU rejects a key that was sent without first requesting a seed.

Reset predictability

Opt-in: checks whether the same seed returns after an ECU reset, a sign of clock- or uptime-seeded generation.

Grounded method

The test cases mirror established research (CaringCaribou for seed randomness, HydraVision for lockout).

FAQ

Frequently asked questions

Is this destructive?

The core probes are bounded and non-destructive. The one exception is the optional ECU-reset predictability probe, which resets the ECU and is therefore gated behind an explicit confirmation.

What counts as a weak key algorithm?

If AutoST can derive the key from the seed with a simple transformation, or a default key from a known catalogue unlocks the ECU, the seed/key scheme is reported as weak.

See it on your ECU

Run AutoST on your own ECU

In one hour we scope a pilot: your bench, your protocols, the targets and what success looks like.

  • A concrete test plan for your setup
  • Works on CAN, CAN FD, DoIP and SOME/IP
  • NDA on request before we start
Tom Zaubermann

Your demo is withTom ZaubermannFounder of Zyberum, ex-lead of the VW InCar Security Testing Lab

Already trusted by Tier 1, Tier 2 suppliers and OEMs. References on request.

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usPlan a pilot

Pick a time that suits you

Open in a new tab