DuoKey

Volkswagen · Automotive

OTA that stays under OEM authority.

Vehicle software changes in the field. Signing and certificates have to keep up without stopping the line.

The problem

If update keys sit only with a cloud operator, the OEM cannot prove who authorised a change. Expiry then stops aftersales.

How DuoKey helps

DuoKey keeps PKI and signing with the manufacturer, including at the edge, on the platforms already in production.

Security leadership

The questions this programme had to answer

What changed

How DuoKey closes the OTA control gap

  • OEM

    Signing stays with the manufacturer

    Cloud can host the update service. It does not hold the last word on vehicle software.

  • Edge

    Credentials work where cars operate

    Keys used in the field remain under OEM custody, not only in a central tenant.

  • OTA

    Rotation without stopping updates

    Certificate lifetime matches production cadence instead of creating an outage window.

  • Proof

    A record for type-approval reviews

    Security and engineering can show who signed what, when and under which policy.

Parlons des décisions qui comptent pour votre programme de sécurité.

Dites-nous où le contrôle est difficile aujourd’hui. Nous vous aiderons à définir une prochaine étape concrète.