This page was machine-translated and may differ from the original. View original
Digi-Key: "In the hyper-connected era, embedded development requires built-in security across all aspects of law, technology, and operations."
Global regulations strengthen manufacturer responsibility, requiring risk assessment, lifecycle management, and continuous updates.
Hardware isolation, zero trust, and supply chain security are key, while ensuring data integrity and trust are crucial.
Hardware isolation, zero trust, and supply chain security are key, while ensuring data integrity and trust are crucial.
As connected devices become more prevalent in our lives, the need for robust embedded security has never been greater.
At a recent 'Let's Talk Technical' roundtable, I sat down with experts from leading embedded systems and micro-solutions companies Analog Devices, STMicroelectronics, NXP, and Microchip Technology to hear their insights on the evolving embedded security landscape and its critical role in today's connected world.
While data centers operate in controlled environments with physical safeguards, embedded devices operate in "wild" environments, such as vehicles, appliances, and medical devices.
Therefore, a robust distributed protection strategy is required, unlike centralized data centers that may be vulnerable to physical tampering such as side-channel attacks.
To realize the distributed nature of embedded devices, security must be built in from the beginning, not added later.
Now, embedded system security, navigating new global regulations, advanced Let's look at some insights into the concept.
Cyber Resilience Act: Proposing Strengthened Standards
NXP's Carlos Serratos explains how the Cyber Resilience Act (CRA) shifts responsibility to manufacturers.
CRA compliance affects manufacturers not only in Europe but also around the world.
CRA requires risk assessments for hardware and software, countermeasures for identified threats, and vulnerability reporting throughout the product lifecycle.
This enables us to meet new security expectations at every layer of the value chain, from microcontrollers to finished products.
Security is not just a best practice; failure to comply can result in fines and reputational damage, making it a legal obligation.
Doug Gardner of Analog Devices added that regulations such as NIST, PSA, IEC 62443, and ISO 21434 are shaping development workflows across the industry.
Enterprises must integrate cryptographic primitives, isolation mechanisms, and secure identity management into their engineering processes.
To help developers manage these growing requirements, chipmakers are providing tools, SDKs, and lifecycle monitoring solutions that simplify compliance and reduce the risk of implementation errors.
This support allows developers to integrate security without undue complexity.
Microchip's Xavier Bignalet provided an overview of threat modeling, which defines the risk environment for each device and application.
He said that modern development process should include life cycle management after production and regular updates.He explained that the security of the device must be maintained even after deployment through site monitoring and incident response.
He also emphasized that security doesn't end with deployment; continuous monitoring, firmware updates, and incident response are essential to maintaining resilience against evolving threats.
■ Security Design Principles
Mena Roumbakis of STMicroelectronics emphasized that strong security starts early, from the very beginning.
Developers should perform risk assessments and follow secure coding practices from the initial design stage.
Additionally, you must implement secure boot and zero-trust systems, ensure supply chain integrity, and maintain documentation to support regulatory compliance.
These principles ensure trust from silicon to the cloud.
Experts also discussed the importance of a secure supply chain and the use of zero-trust programming to protect private keys, IP, and firmware from tampering during the manufacturing process.
Gardner emphasized zero-trust systems, explaining how hyper-connected devices must continually verify trust before exchanging data.
As AI and machine learning move to the edge, ensuring the authenticity and reliability of data becomes increasingly important.
■ Advanced security concepts
The expert panel also looked at Secure Enclave technology, an isolated hardware environment designed to protect critical keys and processes.
NXP, Microchip, Analog Devices, and STMicroelectronics are each developing cryptographic authentication, TEE (Trusted Execution Environment), and TruWe implement this concept in various ways, through terms like stZone.
Although the brands differ, the core principles of protecting credentials, ensuring trusted execution, and complying with evolving regulations are similar.
The Secure Enclave concept is central to modern embedded security.
It operates as an isolated environment within the processor, similar to a hotel safe, and is designed to protect sensitive data and perform critical security functions.
Secure Enclave combines hardware and software mechanisms, including hardware isolation, a secure execution environment, secure boot and authentication, cryptographic processing, and runtime integrity monitoring.
These solutions reduce the attack surface by physically and logically isolating sensitive tasks from normal processing and ensure a hardware-based root of trust.
As AI and machine learning move to the edge, ensuring data authenticity and integrity becomes increasingly important.
The panel emphasized that complexity is the enemy of security and stressed the importance of isolation and layered defenses.
Because large-scale systems like operating systems inevitably have flaws, critical assets like encryption keys must be stored in a highly secure environment to prevent catastrophic "break one, break all" attacks.
Real-world examples, such as vehicles being remotely hacked through their entertainment systems, highlight the importance of these measures.
The concept of isolation isn't new—it's been used for decades in credit card chips, SIM cards, and TPMs—but it's now expanding across the industry.
Technologies like ARM TrustZone enforce hardware to execute critical code. It provides an additional layer of protection by creating a secure state and maximizes protection by complementing dedicated security elements.
■ Conclusion
Finally, Bignalet highlighted the legal and operational consequences of non-compliance.
Organizations that fail to integrate security features into their product designs risk not only security breaches but also potential litigation under new global standards.
Security is no longer an option; it is a legal, operational, and ethical imperative.
Industries are working to build trust across all layers of connectivity to ensure resilience in a highly connected world.
※ ContributorShawn Luke is a technical marketing engineer at DigiKey. DigiKey is a global leader and innovator in the advanced commercial distribution of electronic components and automation products, offering more than 17 million components from over 3,000 leading, name-brand manufacturers.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















