As an essential component of edge computing, embedded computers are increasingly being deployed across all industry sectors. Ensuring their ongoing reliability and protection from cyber and physical threats must now be a top priority for IT and OT (Operational Technology) teams to secure the future of corporate edge architectures.
The Growing Challenge at the Edge
The IT and OT requirements are at risk of becoming irreconcilable as edge computing models continue to expand. IT departments are focused on security, while OT teams prioritise operational efficiency and business agility. Overcoming this will require collaboration and innovation from the embedded computing industry.
The rapid growth of edge networks means countless devices now reside inside corporate firewalls, with those firewalls themselves extending further ‘into the wild’ via software-defined wide area networks (SD-WAN). While some devices are easy to monitor, many are so deeply embedded they risk being physically exposed to abuse.
This presents serious security implications:
- Most ‘smart’ objects have been designed with minimal cybersecurity in mind.
- The wider attack surface puts corporate networks at increased risk from hacks and viruses entering through a ‘back door’ via infected or cloned edge devices.
- Insecure devices can lead to plant, equipment, and localised system failures.
- Insufficient safeguards can allow unauthorised devices to be added or removed from the network unchecked.
Mitigating these risks requires a centralised strategy for device procurement, deployment, monitoring, and maintenance.
Enabling Secure and Reliable Edge Computers
Turning a classical embedded computer into a secure server by embedding firewall and router functions that can be managed remotely is the solution. This allows for continuous, real-time monitoring to secure all devices from logical or physical attacks, wherever they are located.
New IT strategies and technology platforms are needed to achieve this. These solutions must be easy to administer centrally, allowing for rapid implementation across multiple devices. For example, our SEC-Line is a compact solution designed to ensure the rapid implementation and ongoing security of multiple edge computers.
This is achieved through a combination of leading-edge technologies, including:
- Open Platforms – These connect the physical and virtual worlds.
- Operational Applications – These run securely inside virtual machines for payload insulation and consolidation.
- Embedded Firewalls and Routers – These protect generic network connections.
- Centralised Management – This allows for the management of all firmware, network, and software updates from a single point.
- Independence – The systems have zero dependence on the cloud for connectivity, meaning they can function with intermittent connections.
The SEC-Line’s hardware-enforced security relies on firmware based on an augmented version of OpenWrt, which is a leading open-source router/firewall software. This design also includes a secure hypervisor to protect applications and operating systems within virtual machines.
Use Case Deployments
This technology is already proving essential across various sectors.
Transportation
With the ongoing digital transformation of rail networks, operators need secure, easy-to-install embedded computers. Our fanless, industrial-grade computers, like the SR-TRACe-G40x edge server gateway, are certified for rail use. Combined with SEC-Line, they become SR-TRACe-G, offering out-of-the-box router, firewall, and unified communications functionality, just like a branch office uCPE (universal customer premise equipment).
Naval Defence
In defence, operators are moving away from privately owned and controlled architectures towards open IT standards. This allows for more cost-effective system designs and the use of COTS (commercial off-the-shelf) servers. However, the increased deployment of open, cloud-based mission-critical systems requires greater visibility and security for computers at the edge, such as those on board naval warships. Edge systems monitoring and maintenance platforms like SEC-Line are therefore becoming a necessity.
Static and Legacy Workloads
Many legacy applications use old operating systems and libraries. The virtualisation layer of Kontron’s firmware is used to protect and deploy these applications, unmodified, in virtual machines. The security is derived from the hardware root of trust, which is protected by firmware with modern firewall and cyber defence mechanisms. This allows OT teams to safely deploy old stacks in modern, always-connected mission profiles with almost no code development.
Embedded computing is morphing into edge computing, where systems are continuously connected and exposed to threats. Deployments can involve hundreds of computers, which need specific tools to achieve security, operational efficiency, and business agility. Industrial Computers Ltd is addressing these growing edge-driven threats with a clear approach, allowing IT and OT experts to collaborate effectively and achieve a secure, future-proof computing environment.
Harness the power of embedded computers to secure your IoT architecture.
Don’t let the expanding edge create security risks—implement solutions like our SEC-Line today to centralize management, embed critical firewall/router functions, and achieve the operational efficiency and business agility your enterprise needs. Get in touch with our experts or call us on +44 (0)1243 523 500 to future-proof your connected environment.
