Embedded Security for CRA Requirements

Security-by-Design for Embedded Systems: From TARA to Security Testing

The Cyber Resilience Act (CRA) raises the bar for the security of connected products. For manufacturers, this means incorporating security considerations early in the product development process. Technical security requirements do not arise only at the end of a project. They influence requirements, architecture, hardware selection, software design, communication interfaces, update concepts, and subsequent validation.

Security for embedded systems

Addressing security requirements early

Hitex supports companies in the technical implementation of CRA requirements in embedded systems. Our services range from TARA to Security-by-Design and Development, to security validation and security testing. This is based on established standards and proven technologies such as IEC 62443, ISO/SAE 21434, Secure Boot, Arm TrustZone, and more.

Contact Security Experts
Learn more

What does the Cyber Resilience Act mean for embedded products?

The Cyber Resilience Act (CRA) increases the cybersecurity requirements for products with communication interfaces. In addition to technical protective measures, risks must be analyzed, security requirements defined, and appropriate security mechanisms implemented. This includes, among other things, updates, communication, access protection, and the safeguarding of critical functions.

Security is not achieved through individual technologies alone, but through a systematic approach and the use of the right technology.

Typical steps include:

  • Analyzing risks
  • Deriving security requirements
  • Defining the security architecture
  • Implementing security functions
  • Validating security measures

This ensures that security requirements are integrated into development at an early stage and supports “security by design.” Hitex can help you, for example, by extending the traditional development process to include security requirements, security architecture, security implementation, and security testing.

Where does Hitex provide support?

Threat Analysis and Risk Assessment (TARA)

A TARA identifies potential attack paths and assesses risks within an embedded system. Standards such as IEC 62443 and ISO/SAE 21434 use TARA and equivalent methods as a key method for deriving security requirements.

Hitex provides support with:

  • Identifying relevant threats
  • Analyzing potential attack paths
  • Assessing risks
  • Deriving technical security requirements
  • Preparing the security architecture

Security-by-Design

Security should be part of product development from the very beginning.

Hitex provides support with:

  • Selecting suitable microcontrollers
  • Selecting suitable operating systems
  • Selecting security components
  • Architectural decisions for secure embedded systems

For more information, see the Security Engineering and Requirements Engineering sections.

Development of secure embedded systems

The security requirements derived from the TARA must be implemented in hardware, software, and architecture. Hitex provides support for implementing specific development tasks such as:

  • Extending existing development processes
  • Implementing technical security requirements
  • Developing security-relevant software
  • Integration of security functions into embedded products

You can find more about our offerings in the Engineering Services section.

Security Validation & Security Testing

Security measures must be verifiably effective. Security testing is a distinct component of the development process.

Possible areas where you can rely on Hitex include:

Technologies for secure embedded systems

Depending on the results of the TARA and the system’s requirements, different security mechanisms like Secure Software Updates and Boot Processes,  Cryptography, and Isolation of security-critical functions are employed.

Secure software updates and boot processes

Secure firmware updates and Secure Boot (embedded bootloader) ensure that only authorized software is executed, tampering is detected early, and the integrity of the system is maintained.

Cryptography and protection of sensitive data

Securing communication, updates, and data is often based on cryptographic methods, key management, and secure storage mechanisms. With Embedded Security Components, Arm Encryption Libraries, and Security Stack for HSM, Hitex supports you in developing secure systems.

Isolation of security-critical functions

Arm TrustZone enables the separation of the Secure World from the Non-Secure World. This allows security-critical functions to be isolated from normal application functions. As an architectural principle, this approach can be applied to both Arm-based systems and comparable security concepts on other platforms, such as AURIX™, which serve as the technological foundation for modern embedded security.

Why Hitex for embedded security?

Hitex combines functional safety, embedded security, and engineering in embedded product development. Security measures are not considered in isolation but are integrated into existing development processes.

Your benefits at Hitex:

  • Embedded focus
  • Experience with safety and security requirements
  • Support from TARA to security testing
  • Expertise in Arm®-, AURIX™-, and RISC-V-based systems
  • Engineering expertise for hardware and software

Practical knowledge in embedded security and CRA

Our experts deal with functional safety, embedded security, and the development of secure embedded systems on a daily basis.
We regularly share this expertise with technical articles and white papers (like Cybersecurity with Arm® TrustZone as the technological foundation), security requirements in product development, training courses on functional safety, and training courses on embedded security.

Presentations and industry events

Our experts regularly speak at industry events, and conferences, presenting on topics such as the technological basis for the Cyber Resilience Act (CRA), embedded security, security-by-design, functional safety, and more. You can find the latest events on our Events page.

Frequently Asked Questions (FAQ) about embedded security

Topics

Learn all about functional safety

Functional Safety

Hitex engineers have deep expertise in developing safety-critical software solutions that comply with safety standards like ISO 26262 and IEC 61508.

Find out more about FuSa
Learn more
More about Security

Embedded Security

Hitex develops security architectures that safeguard embedded systems from unauthorized access, data breaches, and malicious attacks.

More about Security
Learn more
Motor control, battery management and energy efficiency

Energy Efficiency

Our software engineers specialize in optimizing embedded systems for energy efficiency across various applications.

Energy efficiency
Learn more
E-Mobility

E-Mobility

Our software solutions enable enhanced performance, improve charging infrastructure, and intelligent energy management.

E-mobility revolution
Learn more
safety standards such as ISO 26262

Standards

We help you to comply with safety standards such as ISO 26262 and safety requirements such as ISO 21434.

Learn more
Learn more
Microcontroller

Microcontrollers

Everything at Hitex revolves around the microcontroller. Development, programming, software and safety & security.

We love microcontrollers
Learn more