The basis for safe industrial devices

Industrial equipment, control systems and networked systems are now at the centre of regulatory requirements and growing cyber threats. Under the Cyber Resilience Act (CRA), manufacturers of digital products are required to incorporate security from the outset – throughout the entire lifecycle.

Embedded security is not an optional feature. It is the technical prerequisite for ensuring that devices can be operated securely within industrial networks and critical infrastructure.

SYS TEC electronic develops secure embedded systems for the industrial, building services, energy and defence sectors – with a clear focus on ‘security by design ’ and compliance with the IEC 62443 standard.

Cyber Resilience Act (CRA): Why embedded security is crucial today

The CRA requires manufacturers of digital products, amongst other things, to:

  • Security by Design
  • Secure update capability
  • Vulnerability management
  • Demonstrable product security throughout the entire lifecycle

Without integrated security mechanisms, market access will become considerably more difficult in future. Security will thus become a regulatory requirement.

Would you like to gain a structured understanding of the CRA’s requirements?


Training course: Basic knowledge of embedded security and the Cyber Resilience Act

How can the CRA be applied in practice to existing or new products?


Workshop: CRA in practice

Embedded security as the foundation of cyber security

Security over the entire life cycle

Product safety does not end with delivery. The key factors are:

  • Long-term updateability

  • Vulnerability management

  • Maintainability over many years

  • Scalable update strategies for large volumes

Especially in markets such as industrial, energy technology, building technology and defence, the long-term protection of systems is a key success factor.

Cyber security protects networks and infrastructure.

Embedded security ensures that the individual device itself is trustworthy.

Only if:

  • the firmware is authentic,
  • no unauthorised debug access is possible,
  • cryptographic keys are protected,
  • updates can be installed securely,

can a device be reliably integrated into an overarching cyber security strategy.

Embedded security is therefore the foundation of any holistic security architecture.

Practical in-depth training for development and project teams:

Cybersecurity workshop for embedded systems

Technical implementation of embedded security

Secure Boot - protection of the system integrity

Our sysWORXX ECUcore-AM62x platform utilises the TI Sitara™ AM623 processor with integrated secure boot functionality.

Secure Boot ensures that only signed and authorised firmware is started. Manipulated or unauthorised images are blocked.

Advantages:

  • Protection against firmware manipulation
  • Ensures the integrity of the system
  • Trusted system start(root of trust)

We are already using Secure Boot successfully in various customer projects.

Secure software updates – locally and OTA

Modern products must remain capable of being updated for many years. We implement secure update mechanisms via:

  • USB
  • Ethernet
  • serial interfaces
  • OTA (Over-the-Air)

All update processes can be cryptographically secured:

  • Signed update images
  • Integrity checks
  • Authenticated update processes

RAUC A/B update concept

We rely on an A/B partition concept for high availability:

  • Update takes place on the inactive partition
  • Automatic rollback in the event of errors
  • Minimised risk of failure

Hardware-based security measures

Security does not end with the software.

Protection of critical signals in PCB design

  • Routing sensitive traces in inner layers
  • Reducing opportunities for tampering and tapping

Disabling or securing JTAG

  • Prevention of unauthorised debug access in the field
  • Optional controlled debugging capabilities for servicing purposes

TPM / dedicated security chips

  • Secure key storage
  • Cryptographic functions
  • Unique device identity
  • Support for secure communication protocols

Embedded Linux & Security Engineering

Secure embedded systems require a deep understanding of build and integration processes – particularly on Linux-based platforms.

In-depth technical session for experienced developers:

Expert workshop: Embedded Security Engineering with Yocto

IEC 62443 and Defence-in-Depth

The international standard IEC 62443 defines requirements for the security of industrial communication networks and systems.

A central principle is defence-in-depth - multi-layered protection:

Embedded security addresses the component level in particular and forms the basis for higher security levels within an overall industrial architecture.

Our development processes are based on IEC 62443-4, even if no formal certification is currently being sought.

Security by design

Security starts with the architecture

For us, ‘security by design’ means:

  • Security requirements are taken into account right from the concept phase
  • Hardware and software architecture are specifically designed to meet security requirements
  • Security mechanisms are an integral part of the design

Our development process is guided by the requirements of IEC 62443-4 (Secure Product Development). At the same time, we develop our systems so that they can be used as industrial components within the context of IEC 62443-3 (OT security).

A key component of Security by Design is structured threat analysis.

How are threats systematically identified and assessed?

Threat Modelling Workshop

Embedded Security with SYS TEC electronic

We connect:

  • Our own high-performance platform technology
  • Security-focused architecture
  • Industrial development expertise
  • Understanding of regulatory requirements (CRA, IEC 62443)
  • Customised implementation

This results in robust, secure and future-proof embedded systems for demanding applications.

Logo der Allianz für Cyber-Sicherheit des BSI

Involvement in the Alliance for Cyber Security

SYS TEC electronic AG is a member of the Alliance for Cyber Security, an initiative launched by the Federal Office for Information Security (BSI) to strengthen cyber security in Germany. Through this network, we receive up-to-date information on cyber threats, security alerts and recommendations from the BSI, which we incorporate into our embedded security and cyber security concepts.

Our platform as a technology carrier: sysWORXX ECUcore-AM62x

With the sysWORXX ECUcore-AM62x, we have developed a high-performance embedded platform which we use as a technology platform for custom designs.

Your benefits:

  • Industrial-grade hardware platform
  • Integrated secure boot support
  • Pre-implemented security mechanisms
  • Reduced development risk
  • Faster time-to-market

You’ll benefit directly from all the groundwork we’ve put into this platform – including its security architecture and secure boot and update strategies.

Find out more about the capabilities of the ECUcore-AM62x!

Get in touch now

Ihr Vertriebsteam der SYS TEC electronic

Your contact person: Ihr Vertriebsteam der SYS TEC electronic

Department: We're happy to help:

Email: sales@systec-electronic.com
Phone: +49 3765 38600-2110

Search the website

The internal search function finds pages, documents and blog posts.
Please enter a search term.

What are you looking for?

Frequently searched for:

  • EMC testing
  • Project management
  • Prototype manufacturing
Cookies and Data Protection
Exit the dialogue box and return to the top of the page