Embedded Security

Embedded security is relevant to a wide range of products. Whether in household appliances, programmable logic controllers, or vehicles—we find so-called embedded systems everywhere. These components often perform highly specialized and critical tasks, making them key elements in networked systems. And they are frequently the target of cyberattacks. 

Product Development Based on Security-by-Design

More and more products and devices are connecting to the Internet of Things (IoT). As a result, the number of complex modern embedded systems is steadily increasing. And with it, the potential for attacks. In addition, embedded developers must keep pace with constantly evolving regulations and standards. And ideally, they should incorporate security right from the start of the development process (“Security by Design”). These and other critical aspects must be addressed here: 

Secure Identities for Products and Devices

For IoT security, the unique and tamper-proof identity of a product or device is crucial. This allows them to be reliably authenticated and authorized to prevent unauthorized access. Technologies such as digital certificates, cryptographic keys, and secure hardware elements play an important role here.

Efficient Implementation of Security Measures Given Limited Resources

During product development, security often takes a back seat to functionality and profitability. Despite this pressure, security is a key success factor for products and devices that ensures customer satisfaction. Therefore, measures must be implementable with minimal effort and achieve their intended results. 

Risk of Physical Attacks

IoT devices are often installed in physically accessible environments, making them vulnerable to direct tampering. Attackers could open them, extract firmware, or tamper with hardware components. This would give them access to sensitive data or allow them to disrupt functions. To make physical attacks more difficult, techniques such as tamper-resistant enclosures, secure boot processes, and encrypted storage are employed.

Cyber Resilience Act: Understanding and Implementation

Since September 2024, Prof. Dr. Dominik Merli, Professor of IT Security and Director of the Institute for Innovative Security (THA_innos), has been guiding companies through the CRA process using THA_innos’s expertise. Tailored to the perspective of manufacturers. Learn more about the CRA on the blog and find answers to frequently asked questions.

Finding Solutions with THA_innos

Industry and other organizations work with THA_innos to overcome their technical and organizational challenges—from workshops and customized contract work to collaborative research projects.

More about THA_innos

The Institute for Innovative Safety and Security at the Technical University of Applied Sciences Augsburg (THA_innos) helps organizations of all sizes operate safely and sustainably in an interconnected world. Through the institute’s innovative approaches, systems, products, and personnel become resilient against digital threats to the economy and society.