• No results found

APPLIED AND INTEGRATED SECURITY

N/A
N/A
Protected

Academic year: 2021

Share "APPLIED AND INTEGRATED SECURITY"

Copied!
21
0
0

Loading.... (view fulltext now)

Full text

(1)

© Fraunhofer

APPLIED AND INTEGRATED SECURITY

Directors:

Claudia Eckert (Managing) Georg Sigl

(2)

© Fraunhofer

SECURITY RESEARCH IN MUNICH

2

Fraunhofer Institution for

Applied and Integrated Security

Claudia Eckert Georg Sigl

TU München

Computer

Science

Claudia Eckert

TU München

Electrical

Engineering

(3)

© Fraunhofer

AISEC MISSION:

MIT SICHERHEIT INNOVATIV!

 Development of innovative Security Technologies

 to improve Robustness, Dependability and Security of IT-based Systems and Infrastructures

 Development of innovative, new Applications

 to improve existing (IT-based) Workflows and  to enable new Business Models

 Development of Test Methods and Tools

 to improve the Quality of Products, Designs, Applications, …  to minimize Risks and reduce Damages

(4)

© Fraunhofer

AISEC KEY FIGURES

 Employees: 2013: current status: 98 (incl. 62 FTEs) Plans for further growth

 2014 > 110

 2015 > 150 Financing (Fraunhofer Model)

(5)

© Fraunhofer

AISEC

FIELDS OF EXPERTISE

Embedded Security

Smartcard & RFID Security

Product Protection

Cloud Security

Network Security

Automotive Security

Smart Grid

Security Evaluation

Mobile Security

(6)

© Fraunhofer

(7)

© Fraunhofer

EMBEDDED SECURITY

RESEARCH & DEVELOPMENT AREAS

Secure (wireless) Transaction Systems

e.g. Remote Keyless Entry (RKE) based on elliptic curves

Concepts for Component Identification/Authentication

using Physical Unclonable Functions (PUF)

Hardware Security Modules (HSM)

as hardware trust anchor

Mechanism for Product and Piracy Protection

to prevent cloning and IP theft

Trustworthy Platforms and Virtualization

as a secure software environment

Methods and Tools

to support designers in secure software design and verification

(8)

© Fraunhofer

SECURE SERVICES

RESEARCH & DEVELOPMENT AREAS

Cloud Security:

Security-Monitoring-Framework

TapnDrop: Secure Data

Exchange (e.g. in meeting) using Cloud Backend Storage

Secure Distributed Storage

Mobile Security:

Security Analysis Framework for Android

 Vulnerability Assessments

AppRay: App-Security Checks

to be integrated e.g. in »Company App Store«

Development Monitoring Testbed

Cloud

Portfolio

Penetration Test

Test-Frameworks Compliance &

Interoper- ability Analysis Interoperability Whitepapers Knowledge Security as a

(9)

© Fraunhofer

NETWORK SECURITY

RESEARCH & DEVELOPMENT AREAS

Network Security:

 Security Architectures for Secure Cloud-Networking

 Software Defined Networking (SDN): Security Analysis, new Security Protocols & Applications

Cyber Security:

 New and improved attack detection techniques

 Collaborative information exchange between e.g. operators, information exchange w/o loss of reputation

System & Network Evaluation and Test

 PRIvacy VIolation DetectOR: Tool to support website analysis

(10)

© Fraunhofer

AISEC Security Analysis Labs: Examples

Hardware Security Lab

 Analysis and validation of HW components & security modules

NFC Lab

 Analysis of NFC solutions, e.g., mobile payment

Smart Meter Lab

 Vulnerability assessment of Smart Meter and Gateways

Network-Lab

 Malware Analysis, SDN-Lab, HIP („IPSec2.0“)

Cloud-Lab

 Interoperability tests on OpenSource Stacks, Security as a Service

Mobile Lab

(11)

© Fraunhofer

Hardware Security Lab

Attacks and Analysis

 (Differential) Power analysis (SPA, DPA)

 Template attacks

 Electromagnetic Radiation Analysis (EMA)

 Fault Attacks

 Temperature Attacks

Offerings

 Security Analysis (Black Box, White Box)

 Design Verification

(12)

© Fraunhofer

SMART GRID

Secure Smart Meter

Problem

Attacks on Control Systems

Fraud

Privacy Protection

Innovative Solutions

Security Concepts for Smart Meter

and Gateways

Adapted Hardware Security Modules and

Efficient (Cryptographic) Protocols

Concepts for Anonymity and Pseudonyms

Advantage

Development of Smart Grid Reference

(13)

© Fraunhofer

TAPNDROP: SECURE FILESHARING

THROUGH THE CLOUD

 Data Exchange via Cloud

 Spontaneous Data sharing in

a Meeting between present People

 Client-side Encryption 

no Trust in Cloud Provider required

 Key Exchange through NFC: AES256 Session Key

 Session-Management: Limited Key Validity

13

(14)

© Fraunhofer

APP-RAY: AUTOMATIC APP SECURITY CHECK

 Automated Check of Android-Apps for  Security Weaknesses

 Privacy Violations

 User defined Catalogue of Criteria 14

(15)

© Fraunhofer

AISEC PARTNERS*

(16)

© Fraunhofer

NETWORKING

Cloud security Alliance WWR ETSI Organisations Embedded Alliance

Collaborative Work: e.g. ILT, IIS, EMFT, IWES, Fraunhofer Computer Science Electrical engineering TU Munich BICCnet (Security cluster) Eurosmart TCG Car2Car AISEC Associations Cloud Alliance Kantara Münchner Kreis TeleTrust GFFT CAST eV GESA VDE/ITG BITKOM Safetrans Other Research Institutions

(17)

© Fraunhofer

Technische Universität München

SICHERHEITS-CLUSTER MÜNCHEN

(18)

© Fraunhofer

Mobile Security

Secure Cyber Physical Systems Security Evaluation CC Cyber- Security CC Test & Simulation CC Cloud & eID Cyber Security Center

Industry & Appilcation Partners Research Partners Ulm Passau Erlangen fortiss

THE FUTURE

(19)

© Fraunhofer

AISEC SERVICES AND OFFERINGS

Studies

risk analyses, evaluation of technologies and concepts  Tests

vulnerability analyses, technical pre-auditing  Development

concepts, proofs-of-concepts, implementation, integration  Modeling

security concepts, optimization of infrastructures & solutions  Training & Consulting

(20)

© Fraunhofer

OUR STRENGTHS

 Our labs provide ideal environment for evaluations.  Security analysis and testing

 Interoperability testing, conformance testing

 We have the right competences, environment and labs to  design prototypes demonstrating tailored solutions,

 develop proof-of-concepts demonstrating improved solutions

 Our knowledge about all layers:  Hardware, Embedded,

 Networking,

 Services, Cloud, Processes

allows us to provide holistic security solutions.

(21)

© Fraunhofer

THANK YOU

Contact:

Georg Sigl: [email protected]

[email protected]

Claudia Eckert: [email protected] [email protected]

References

Related documents

Park et al, 1999 ). The two maize genes are compared to their shared single orthologs in the Sorghum, fox- tail millet, rice and Brachypodium genomes. The conserved

REC, as well as its directors, officers and employees, shall not be responsible for and disclaims any liability for any loss or damages, including without limitation, direct,

Under no foreign exchange market intervention, the central bank responds to a negative money demand shock by raising the domestic in- terest rate while allowing some

Background and Purpose: In this multicentric in silico trial we compared photon, proton, and carbon-ion radiotherapy plans for re-irradiation of patients with squamous cell carcinoma

公司( Monsanto Chemical Company)生产的 Aroclor。Aroclor 的氯取代程度通常 用一个四位数字表示,其中前两位数字表示 PCB 混合物,后两位数字表示

There were present: Councilman David Ball Councilman James Boudreau Councilman Laurie Marble Councilman Frank McClement Supervisor John Lawler.. Supervisor Lawler made a

(1) To assess how well medical residents recognize clini- cally relevant potential DDIs; (2) to determine the current DDI information sources used by residents, their desire to

Cloud Mgmt SW Enterprise Mgmt SW Other Mgmt SW Nova drivers Server Cinder drivers Storage Network AMQP DBMS Infrastructure Mgmt Capabilities Image Management. Virtual