Projekt
aCtive sEcurity foR connecTed devIces liFecYcles
Cyber-attacks get more sophisticated every day, thus affecting a large number of IoT-related infrastructures and raising security and privacy concerns of consumers and businesses. Security management of IoT infrastructures encompassing full lifecycle of products and continuous certification are fundamental tools to gu…
Cyber-attacks get more sophisticated every day, thus affecting a large number of IoT-related infrastructures and raising security and privacy concerns of consumers and businesses. Security management of IoT infrastructures encompassing full lifecycle of products and continuous certification are fundamental tools to guarantee a high-level of security, as emphasized by the European Union Agency for Cybersecurity (ENISA) Cybersecurity Act (CSA).
CERTIFY defines a methodological, technological, and organizational approach towards IoT security lifecycle management based on (i) security by design support, (ii) continuous security assessment and monitoring (iii) timely detection, mitigation, and reconfiguration, (iv) secure IoT Over-The-Air (OTA) updating, and (v) continuous security information sharing.
To ensure the security compliance throughout the lifetime of the device, we propose the design and implementation of a cybersecurity lifecycle management framework for IoT devices. The framework is intended to support the device security management by collecting and sharing relevant security information both internally (via monitoring and self-assessment services) and externally, e.g., by interacting with device manufacturers, threat databases, certification authorities, Information Sharing and Analysis Centres (ISACs), and more. The received information is meant to support the local decision making with respect to the security, monitoring, updating and configuration of the device. Moreover, this information sharing will enable a continuous risk assessment, gathering evidence that could agile future certifications.
CERTIFY's provides IoT stakeholders with mechanisms achieving high-level of security. CERTIFY will detect and respond to a wide spectrum of attack, in a collaborative/decentralized fashion. CERTIFY will validate the architecture through cutting-edge use-cases and pave the way towards innovative security in a broad spectrum of IoT environments.
Technologien
- Internet der Dinge Internet der Dinge – Überblick über Forschungsprojekte, Patente und Akteure im TechnologieAtlas.
- Cybersicherheit Cybersicherheit – Überblick über Forschungsprojekte, Patente und Akteure im TechnologieAtlas.
Hochschulen
- FUNDACION INSTITUTO INTERNACIONAL DE INVESTIGACION EN INTELIGENCIA ARTIFICIAL Y CIENCIAS DE LA COMPUTACION FUNDACION INSTITUTO INTERNACIONAL DE INVESTIGACION EN INTELIGENCIA ARTIFICIAL Y CIENCIAS DE LA COMPUTACION –…
- UNIVERSIDAD DE MURCIA UNIVERSIDAD DE MURCIA – Hochschule bzw. Forschungseinrichtung mit Aktivitäten in Forschung und Innovation.
- UNIVERSITAT ZURICH UNIVERSITAT ZURICH – Hochschule bzw. Forschungseinrichtung mit Aktivitäten in Forschung und Innovation.
Unternehmen
- DIGITAL WORX GMBH DIGITAL WORX GMBH – Unternehmen mit Aktivitäten in Forschung und Innovation.
- ADVANCED LABORATORY ON EMBEDDED SYSTEMS SRL ADVANCED LABORATORY ON EMBEDDED SYSTEMS SRL – Unternehmen mit Aktivitäten in Forschung und Innovation.
- Trust Square Service AG Trust Square Service AG – Unternehmen mit Aktivitäten in Forschung und Innovation.
- ENGINEERING - INGEGNERIA INFORMATICA SPA ENGINEERING - INGEGNERIA INFORMATICA SPA – Unternehmen mit Aktivitäten in Forschung und Innovation.
- STMICROELECTRONICS SRL STMICROELECTRONICS SRL – Unternehmen mit Aktivitäten in Forschung und Innovation.
- TRUST UP SRL TRUST UP SRL – Unternehmen mit Aktivitäten in Forschung und Innovation.
- COLLINS AEROSPACE IRELAND, LIMITED COLLINS AEROSPACE IRELAND, LIMITED – Unternehmen mit Aktivitäten in Forschung und Innovation.
Förderungen
- HORIZON HORIZON – Förderprogramm mit geförderten Forschungs- und Innovationsprojekten im TechnologieAtlas.