SCRATCh
SeCuRe and Agile Connected Things
It is difficult to develop and operate secure, large-scale IoT systems. While there are technology platforms that aim to provide the necessary elements for integrating devices and backbone logic, they do not address the security, agility and need for continuous deployment that are the main concerns of modern, software-intensive systems.
SCRATCh is therefore developing an integrative solution approach for IoT, security and DevOps practices. This is being implemented using a toolkit based on a common conceptual architecture. Topics here are a hardware security foundation for strong device identity, DevOps IoT tools for the development and continuous deployment of IoT solutions and a DevSecOps-inspired process to promote security and reliability in IoT applications.

In the SCRATCh project, OTARIS supports tool development in the individual DevOps phases with threat analyses and securing IoT communication. The OTARIS Traffic Analyzer is used here to analyze network traffic. Other research topics include the security of long-range radio protocols and, in particular, security analyses of implementations of the LoRaWAN protocol. We would be happy to use our expertise in the field of IoT security to advise you on your IoT or cloud application or on the introduction of DevSecOps in your company.
Use cases:
- Connected Retail: secure continuous delivery of applications for the deployment and operation of tomorrow's IoT-based retail stores
- Police: Redesigning an existing mobile surveillance platform for secure storage, streaming and delivery
- Smart grids: development of anti-fraud algorithms, blockchain implementations and other security mechanisms
- Smart Machine: Development of an intelligent and secure method for connecting machines
