ZTHA: A Zero Trust Hypervisor Architecture for Software-Defined Vehicle HPC
  • Lim, Seong Hyeon
  • Oh, Sung Bhin
  • Do, Young Soo
  • Kim, Young Min
  • Suh, Beom Gi
  • ... Jeon, Jae Wook
  • 외 2명
Citations

SCOPUS

0

초록

This paper proposes the Zero Trust Hypervisor Architecture (ZTHA) to simultaneously achieve security and real-time performance in the High-Performance Computing (HPC) environment of Software-Defined Vehicles (SDV). ZTHA applies the principle of separating the Control Plane and the Data Plane at the hypervisor level. All new communication sessions are strictly verified by a Gateway VM (the Control Plane) against multi-layered security policies, including VM identity and service access rights. Once a session is verified, its subsequent data packets are transmitted with low latency at near hardware line-rate speeds through a Fast Path established in Open vSwitch (OVS). This "verify first, then accelerate"approach pragmatically implements the principle of Zero Trust while minimizing performance degradation for real-time communications. Experimental results from a prototype demonstrate that ZTHA significantly improves Round-Trip Time (RTT), throughput, and jitter compared to conventional methods, and shows resilience by maintaining the stability of critical systems under attack loads. This study validates that ZTHA is an effective architecture for providing both robust security and deterministic real-time performance in the complex mixed-criticality environments of SDVs.

키워드

Automotive SecurityHypervisorZero Trust
제목
ZTHA: A Zero Trust Hypervisor Architecture for Software-Defined Vehicle HPC
저자
Lim, Seong HyeonOh, Sung BhinDo, Young SooKim, Young MinSuh, Beom GiLee, Chae EunKwon, Kyung DongJeon, Jae Wook
DOI
10.1109/ICCE-Asia67487.2025.11263576
발행일
2025
유형
Conference Paper
저널명
2025 IEEE/IEIE International Conference on Consumer Electronics-Asia, ICCE-Asia 2025