Embedded Security for Mission-Critical Systems
The increasing complexity and interconnectivity of embedded systems significantly expands the attack surface for cyber threats. A single compromised component can enable the theft of intellectual property, ransomware attacks, persistent espionage, or sabotage, with immediate impacts on mission success and system availability.
SANCTUARY offers a comprehensive portfolio of embedded security solutions developed for high-trust and long-lived systems.
Platform Integrity and Trust
Runtime protection limits the impact of faults and attacks during operation. Applications can be isolated using hardware-based trusted computing technologies such as Arm TrustZone or AMD SEV, as well as through real-time hypervisors.
Cryptography and Key Management
Cryptography services include the analysis, design, and secure integration of cryptographic components. Supported technologies include virtual and physical TPMs as well as cryptographic accelerators optimized for performance- and resource-constrained environments.
Public Key Infrastructures
SANCTUARY's Public Key Infrastructure technology is designed for disconnected, long-duration, and hostile environments such as satellite missions. The architecture supports quantum-ready hybrid cryptography as well as the epidemic distribution of revocation information.
Strong Application Isolation
Hardware-based isolation enforces a strict separation between applications and system resources. This prevents unintended mutual interference between applications and supports mixed-criticality workloads, as is common in aerospace and defense systems.
Core Security Capabilities
Embedded systems are becoming increasingly complex as the demand for software services continues to grow. This development is driven by megatrends such as the Internet of Things (IoT) as well as by new application fields, for example autonomous driving. The extensive functionalities of today's embedded systems lead to diverse security and safety requirements for individual systems and simultaneously create highly complex software supply chains. At the same time, embedded systems are almost never isolated stand-alone devices, but rather part of a system-of-systems in which sensitive data is continuously transferred between embedded systems and the cloud.
The increased complexity of embedded systems gives rise to numerous security challenges: from a greater dependence on untrusted open-source software to a higher probability of software vulnerabilities, to an expanded attack surface for cyberattacks. If an embedded system is successfully compromised, an attacker can use it to steal valuable intellectual property, carry out ransomware attacks, deploy it as part of a botnet, or commit acts of sabotage. This can cause significant financial damage.
SANCTUARY Security Services are a unique portfolio of software-based security solutions that can be flexibly combined to effectively protect embedded products:
- Security Designs
- Public Key Infrastructures
- Arm TrustZone
- Confidential Computing
- Secure Boot
- Remote Attestation
- AMD SEV
- Real-time Hypervisors
- Trusted Platform Modules
- Fuzzing & Static Analysis
- Anomaly Detection
- (Post-Quantum-) Cryptography