Embedded Security
Embedded security is relevant to a wide range of products. Whether in household appliances, programmable logic controllers, or vehicles—we find so-called embedded systems everywhere. These components often perform highly specialized and critical tasks, making them key elements in networked systems. And they are frequently the target of cyberattacks.
Product Development Based on Security-by-Design
More and more products and devices are connecting to the Internet of Things (IoT). As a result, the number of complex modern embedded systems is steadily increasing. And with it, the potential for attacks. In addition, embedded developers must keep pace with constantly evolving regulations and standards. And ideally, they should incorporate security right from the start of the development process (“Security by Design”). These and other critical aspects must be addressed here:
Secure Identities for Products and Devices
For IoT security, the unique and tamper-proof identity of a product or device is crucial. This allows them to be reliably authenticated and authorized to prevent unauthorized access. Technologies such as digital certificates, cryptographic keys, and secure hardware elements play an important role here.
Efficient Implementation of Security Measures Given Limited Resources
During product development, security often takes a back seat to functionality and profitability. Despite this pressure, security is a key success factor for products and devices that ensures customer satisfaction. Therefore, measures must be implementable with minimal effort and achieve their intended results.
Risk of Physical Attacks
IoT devices are often installed in physically accessible environments, making them vulnerable to direct tampering. Attackers could open them, extract firmware, or tamper with hardware components. This would give them access to sensitive data or allow them to disrupt functions. To make physical attacks more difficult, techniques such as tamper-resistant enclosures, secure boot processes, and encrypted storage are employed.
Cyber Resilience Act: Understanding and Implementation
Since September 2024, Prof. Dr. Dominik Merli, Professor of IT Security and Director of the Institute for Innovative Security (THA_innos), has been guiding companies through the CRA process using THA_innos’s expertise. Tailored to the perspective of manufacturers. Learn more about the CRA on the blog and find answers to frequently asked questions.
