Development and production processes for secure embedded control devices

Tobias Rauter*, Andrea Höller, Johannes Iber, Christian Josef Kreiner

*Korrespondierende/r Autor/-in für diese Arbeit

Publikation: Beitrag in Buch/Bericht/KonferenzbandBeitrag in einem KonferenzbandBegutachtung

Abstract

Security is a vital property of SCADA systems, especially in the context of critical infrastructure. In this work, we focus on distributed control devices for hydro-electric power plants. Much work has been done for specific lifecylce phases of distributed control devices such as development or operational phase. Our aim here is to consider the entire product lifecycle and the consequences of security feature implementations for a single lifecycle stage on other stages. In particular, we discuss the security concept used to secure our control devices in the operational stage and show how these concepts result in additional requirements for the development and production stages.We show how we meet these requirements and focus on a production process that enables the commissioning of secrets such as private keys during the manufacturing phase. We show that this can be done both, securely and with acceptable overhead even when the manufacturing process is handled by a contract manufacturer that is not under full control of the OEM.

Originalspracheenglisch
TitelSystems, Software and Services Process Improvement - 23rd European Conference, EuroSPI 2016, Proceedings
Herausgeber (Verlag)Springer International Publishing AG
Seiten119-131
Seitenumfang13
Band633
ISBN (Print)9783319448169
DOIs
PublikationsstatusVeröffentlicht - 2016
Veranstaltung23rd European Conference on Systems, Software and Services Process Improvement: EuroSPI 2016 - Graz, Österreich
Dauer: 14 Sept. 201616 Sept. 2016

Publikationsreihe

NameCommunications in Computer and Information Science
Band633
ISSN (Print)18650929

Konferenz

Konferenz23rd European Conference on Systems, Software and Services Process Improvement
Land/GebietÖsterreich
OrtGraz
Zeitraum14/09/1616/09/16

ASJC Scopus subject areas

  • Allgemeine Computerwissenschaft

Fingerprint

Untersuchen Sie die Forschungsthemen von „Development and production processes for secure embedded control devices“. Zusammen bilden sie einen einzigartigen Fingerprint.

Dieses zitieren