SAE J3101-2_202511 PDF | Request Standard
Latest

SAE J3101-2_202511

Hardware Protected Security Environment – Trusted Application Isolation Security Models

Standard by SAE International, 2025-11-17

Available Formats:

  • Availability: Immediate Download
  • Language: English
  • License Type: Single User
  • Updates: Not Included
  • Availability: Request Quote
  • Language: English
  • License Type: Enterprise / Multi User
  • Updates: Included

About This Item

This information report identifies and evaluates isolation building blocks applicable to TA sandboxing within a HPSE. These building blocks can be used to support SAE J3101 TA requirements for sandboxing of TAs and secure communication between TAs. TAs must execute within their own trust domain to prevent compromise of the HPSE and other TAs. TA trust domain isolation strength may vary depending on the risk profile of the TA deployed, hence the requirement for isolation building blocks to match the risk profile. A multitenancy TA HPSE has a higher risk profile than multiple TAs from the same source (e.g., OEM). TA multitenancy must not compromise the security properties of the HPSE (the secure integration and execution of trusted multi-vendor code). In this report, we provide information on the following: HPSE TA use cases and risk profiles HPSE TA isolation building blocks for manufacturers Threat analysis to determine the effectiveness of isolation security models As the ECU E/E architecture continues to evolve, we must consider the following classification of ECUs and System on Chips (SoCs) for which isolation building blocks apply: Application Processor Core(s) Realtime Processor Core(s) Microcontroller Core(s) An ECU can be composed of a Normal Environment and Protected Environment (HPSE). Normal Environment is typically separated into user and kernel level privileges, with applications executing at the user privilege level. TAs only execute within the HPSE, and the HPSE is typically divided into user and kernel level privileges which are orthogonal to Normal Environment privileges. The TAs will execute at the same user privilege level within the HPSE; therefore, the isolation building blocks must be implemented at a higher privilege level, such as the HPSE kernel, to ensure that the sandboxing policy can be enforced. The TAs access to HPSE resources is restricted at load time by the sandbox policy which operates at a higher privilege level to the TAs. This report also differentiates between isolation methods which are applied within the HPSE and isolation methods applied at the ECU level when there is consolidation of ECUs into domain controller or HPC, i.e., isolation abstraction. A vehicle could contain two types of Trusted Applications (TAs) for deployment within a Hardware Protected Security Environment (HPSE): TAs developed by the OEM and TAs developed by third-party suppliers. The TAs may require varying strength of isolation mechanisms depending on the source of TAs within the HPSE. We build on SAE J3101 requirements for sandboxing of TAs and secure communication between TAs by providing stakeholders with more technical guidance on sandboxing security model mechanisms. This information report is required to support the TA security requirements within SAE J3101.
SKU: 2ef68cc4d83c

  • Publication Date: 2025-11-17
  • Standard Status: latest
  • Publisher: SAE International
  • Document Type: Ground Vehicle Standard
  • Subject: Hardware, , , , , , , ,
  • Official SAE: Doi link

Please request information about the document. Contact Page

Online Standart App

Need This Standard?

Need This Standard?

Summarize with AI

ChatGPT Perplexity Google AI Claude Grok

Online Standart Disclaimer

OnlineStandart.com is an authorized reseller of international standards, operating through partnerships with authorized distributors. We do not own the copyrights or trademarks of the standards we sell, including but not limited to those of API, ASHRAE, BSI, SAE, ASTM, IEEE, IEC, ASME, ISO, and others.

All product names, logos, and brands are the property of their respective owners and are used for identification purposes only; their use does not imply endorsement. OnlineStandart.com is not affiliated with or endorsed by any standards development organization unless explicitly stated. The content of this document is for informational purposes only and is intended to promote our licensed reselling services.

Online Standart does not host, distribute, or link to free, unlicensed, or uncertified copies of copyrighted standards. Every document we deliver is a licensed copy obtained through authorized channels and supplied with full licensing documentation. The “Free PDF Download” option on our product pages refers to this free informational document — never to a free copy of any standard.