| Zugriffsnummer | 39071 |
| Dokumenttyp | Konferenzartikel |
| Peer Review | mit Peer Review |
| Sprache | Englisch |
| Titel | Software security frameworks and rules for measuring instruments under legal control |
| Autor(in); Institution |
Peters, Daniel; 8.5, Metrologische Informationstechnik, PTB-Berlin
Scholz, Patrick; 8.5, Metrologische Informationstechnik, PTB-Berlin
Thiel, Florian; 8.5, Metrologische Informationstechnik, PTB-Berlin
Nordholz, Jan; Security in Telecommunications, TU-Berlin, Berlin, GERMANY
Seifert, Jean-Pierre; Security in Telecommunications, TU-Berlin, Berlin, GERMANY
|
| Quelle/Jahr | Security and Protection of Information:(2017), 9, 111 - 125 |
| ISSN | 2336-5587 |
| URL | |
| Konferenzangaben | 9th International Scientific Conference Security and Protection of Information, Brno, 1-2, June, 2017, Czech Republic |
| Freie Schlagworte | legal metrology software ; WELMEC 7.2 Software Guide ; MID ; SELinux ; AppArmor ; MAC ; MILS ; separation kernel ; hypervisor |
| Zusammenfassung | Nowadays, measuring instruments are versatile embedded systems that are usually based upon general purpose operating system (GPOS). In the light of the fact that these devices are increasingly connected to the Internet, cyber-security for measuring instruments is of vital importance. In this paper, possibilities to design secure measuring software running on GPOSs, namely Windows and Linux, are analyzed. The framework for measuring instruments which defines the security level and means, is provided by the legal requirements set up by European Directives, e.g. the Measuring Instruments Directive (2014/32/EU). Technical interpretations for the security concepts described in this paper are derived from these legal requirements with the aim to provide manufacturers the architectural guidance to construct systems which easily pass a conformity assessment at a Notified Body. In the first part of this paper security concepts, i.e., SELinux, AppArmor and Mandatory Integrity Control (MIC) are being described, which are based on Mandatory Access Control (MAC) strategies. In the second part, highsecurity methodologies and concepts, e.g., MILS and security kernels, are highlighted and an example based on a ARMv8 board is given. In this example, a new separation kernel called Phidias is used. Hereby, software separation, which enhances overall security, can be achieved by using SELinux mechanisms in the modules (virtual machines) atop this new separation kernel. |
Zitierung
Peters, D., Scholz, P., Thiel, F., Nordholz, J., & Seifert, J.-P. (2017). Software security frameworks and rules for measuring instruments under legal control. 9th International Scientific Conference Security and Protection of Information, Brno, 1-2, June, 2017, Czech Republic.