Next best move:Next: Intercept points Atlas
Guided digital-twin exercise

AutoResilience Trusted Trojan Proof

It entered as something trusted. We proved everything that inherited it.

Safe by design
No live systems · no payloads · no vehicle changes
Step 1 of 13: AuthorisationAuthorisation unlocks the exercise
Start here

Can one trusted supplier identity reach vehicles — and what is the narrowest defensible stop?

This guided emulation reconstructs the trusted path from supplier identity to VIN population, separates affected from independently cleared vehicles, and finishes with an auditable decision receipt. The synthetic reference is already selected, so no setup or customer data is required.

The inheritance route being tested
Trusted source → VIN population
1
Supplier remote-service identity ID-101
2
Tier 2 build environment
3
Signing workflow
4
Firmware release CVG-FW-24.8.17
5
Component lot ECU-LOT-0412
6
Plant SC-01 · Line 2 — Final Assembly
7
Priority VIN population

The exercise follows only relationships that already trust the previous step. It never sends traffic, changes a record or touches a vehicle.

Trace

Follow identity, build, signing, release, lot, line and VIN inheritance.

Bound

Separate affected, verification, cleared and unknown vehicle populations.

Intervene

Identify the narrowest point that stops the next inheritance.

Prove

Leave with evidence, assumptions, owner, deadline and a permanent receipt.

What you do now
  1. Evidence is readyOperation Quiet Passenger is the default synthetic reference. Uploading your own records is optional.
  2. Name three accountable peopleExercise owner, executive sponsor and kill-switch owner are required before the proof can run.
  3. Approve and follow the guideThe next screens walk you through baseline, inheritance, controls, boundary, intervention and receipt.
Digital-twin emulation — no traffic or payload is sent to supplier, production or vehicle systems. No malware, credential, exploit or destructive payload is generated. Connected validation would require separate written authorisation and technical safeguards.

The start button unlocks after the three accountable people are recorded.

Enter names manually
1 · Record authorisation

Approval creates accountability for a decision-support emulation. It does not authorise access to any connected supplier, production or vehicle system.

Review the fixed safety boundaries
Environment
AutoResilience digital twin
Scope
One supplier identity, one build environment, one signing workflow, two releases, three lots, two lines
Authorised suppliers and systems
Synthetic records only — no connected system in scope
Start and end time
On approval → On receipt issue
Data classification
Synthetic — no customer or production record
Approval record
Recorded in this exercise receipt
Evidence retention
Receipt and exercise trail retained with the decision record
Execution mode
Digital-twin emulation only
2 · Evidence for this run
Synthetic reference
Selected

Operation Quiet Passenger uses fictional suppliers, releases, lots, lines and vehicles. Nothing is customer-specific and nothing asserts a real incident.

Your uploaded records
Optional

Upload the CSV templates below to replace the synthetic population counts with your own rows. Files are read in this browser only.

Open templates and upload
Optional — use your own CSV records instead of the synthetic numbers

Download the templates, fill them with your own releases, component lots, lines and vehicles, then upload them here. Every population, reach count and boundary in this proof is then calculated from your rows. Leave this empty to run the fully synthetic Operation Quiet Passenger reference numbers.

Suppliers and remote identities (optional)
Who holds trusted access, and through which identity.
supplier_id, supplier_name, tier, remote_access, identity_id
Software and firmware releases
What was produced under which signing authority.
release_id, software_version, supplier_id, signing_authority, independent_attestation
Component lots
Which lots carry which release.
lot_id, part_number, release_id, quantity
Plants and production lines
Where those lots are scheduled to be installed.
line_id, plant, lot_id, schedule_status
Vehicles in scope
One row per vehicle. disposition must be cleared, verification, containment or unknown; blank or unrecognised values are counted as insufficient information.
vin, line_id, lot_id, release_id, disposition
Why this proof matters
A trusted upstream authority can become the highest-leverage attack target.
Conventional controls may remain green because downstream activity appears legitimate.
AutoResilience can reconstruct the complete inheritance path.
Affected, potentially affected, cleared and unknown populations are distinguished.
Management can interrupt the narrow pathway without stopping the wider operation.
Ready to begin?

Fill the owner, sponsor and kill-switch owner fields — or use the demonstration authorisation.