Zugriffsnummer 39071
Dokumenttyp Konferenzartikel
Peer Review mit Peer Review
Sprache Englisch
Titel Software security frameworks and rules for measuring instruments under legal control
Autor(in); Institution
Peters, Daniel; 8.5, Metrologische Informationstechnik, PTB-Berlin
Scholz, Patrick; 8.5, Metrologische Informationstechnik, PTB-Berlin
Thiel, Florian; 8.5, Metrologische Informationstechnik, PTB-Berlin
Nordholz, Jan; Security in Telecommunications, TU-Berlin, Berlin, GERMANY
Seifert, Jean-Pierre; Security in Telecommunications, TU-Berlin, Berlin, GERMANY
Quelle/Jahr Security and Protection of Information:(2017), 9, 111 - 125
ISSN 2336-5587
URL
Konferenzangaben 9th International Scientific Conference Security and Protection of Information, Brno, 1-2, June, 2017, Czech Republic
Freie Schlagworte legal metrology software ; WELMEC 7.2 Software Guide ; MID ; SELinux ; AppArmor ; MAC ; MILS ; separation kernel ; hypervisor
Zusammenfassung Nowadays, measuring instruments are versatile embedded systems that are usually based upon general purpose operating system (GPOS). In the light of the fact that these devices are increasingly connected to the Internet, cyber-security for measuring instruments is of vital importance. In this paper, possibilities to design secure measuring software running on GPOSs, namely Windows and Linux, are analyzed. The framework for measuring instruments which defines the security level and means, is provided by the legal requirements set up by European Directives, e.g. the Measuring Instruments Directive (2014/32/EU). Technical interpretations for the security concepts described in this paper are derived from these legal requirements with the aim to provide manufacturers the architectural guidance to construct systems which easily pass a conformity assessment at a Notified Body. In the first part of this paper security concepts, i.e., SELinux, AppArmor and Mandatory Integrity Control (MIC) are being described, which are based on Mandatory Access Control (MAC) strategies. In the second part, highsecurity methodologies and concepts, e.g., MILS and security kernels, are highlighted and an example based on a ARMv8 board is given. In this example, a new separation kernel called Phidias is used. Hereby, software separation, which enhances overall security, can be achieved by using SELinux mechanisms in the modules (virtual machines) atop this new separation kernel.

Zitierung

Peters, D., Scholz, P., Thiel, F., Nordholz, J., & Seifert, J.-P. (2017). Software security frameworks and rules for measuring instruments under legal control. 9th International Scientific Conference Security and Protection of Information, Brno, 1-2, June, 2017, Czech Republic.

Exportieren

PTB-Publica MenĂ¼

Sprache wechseln: uk flag