课题基金 / 基金详情

ENTRUST - ENsuring Secure and Safe CMD Design with Zero TRUST Principles

ENTRUST - ENsuring Secure and Safe CMD Design with Zero TRUST Principles
ENTRUST - 以零信任原则确保安全可靠的 CMD 设计
批准号:
10063996
负责人:
金额:
$40.19万
依托单位:
依托单位国家:
英国
项目类别:
EU-Funded
财政年份:
2023
资助国家:
英国
项目状态:
未结题
起止时间:
2023 至 --

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
根据《网络安全法》的指导方针和现有的医疗设备网络安全指导方针,委托设想了一个信任管理架构,旨在动态和全面地管理连接医疗设备的生命周期,加强整个医疗生态系统的信任和隐私。甚至在提案阶段,ENTRUST就已经确定了现行指南的差距和必要的修订(例如,缺乏上市后的一致性和认证,实时监督和纠正机制-见1.2.2)。为此,ENTRUST将利用一系列突破性的解决方案,在不限制联网医疗设备的适用性的情况下,通过将网络安全功能封闭在其中。该项目将引入一种新颖的远程认证机制,以确保设备在运行时的正确运行,无论其计算能力如何;将足够有效地运行在资源受限的实时系统,如医疗设备。这将伴随着动态信任评估模型,能够识别每个设备和功能(服务)所需的可信度水平(RTL),然后通过一种新型高效的认证机制(将在运行时部署和执行)进行验证。这也将使我们能够与现有标准保持一致,以定义每个设备的适当保护配置文件(特别是考虑到不同供应商提供的不同类型的医疗设备具有不同的需求),包括在运行期间验证属性的目标。委托背后的动机是确保医疗设备的端到端信任管理,包括正式验证的信任模型、风险评估流程、安全生命周期程序、安全策略、技术建议和有史以来第一个实时合格证书,以保护连接的医疗设备。
英文摘要
Aligned with the guidelines of the Cybersecurity Act and the existing guidance on cybersecurity for medical devices, ENTRUST envisions a Trust Management Architecture intended to dynamically and holistically manage the lifecycle of connected medical devices, strengthening trust and privacy in the entire medical ecosystem. Even from the proposal stage, ENTRUST has identified gaps and necessary revisions of the current guidance (e.g., absence of post-market conformity and certification, real-time surveillance and corrective mechanisms – see 1.2.2). Towards that ENTRUST will leverage a series of breakthrough solutions to enhance assurance without limiting the applicability of connected medical devices by enclosing to them cybersecurity features. The project will introduce a novel remote attestation mechanism to ensure the device’s correct operation at runtime regardless of its computational power; will be efficient enough to run in also resource-constrained real-time systems such as the medical devices. This will be accompanied by dynamic trust assessment models capable of identifying the Required Level of Trustworthiness (RTL) per device and function (service) that will then be verified through a new breed of efficient, attestation mechanisms (to be deployed and executed during runtime). This will also enable us to be aligned with the existing standards on defining appropriate Protection profiles per device (especially considering the heterogeneous types of medical devices provided by different vendors with different requirements) including Targets of Validation Properties to be attested during runtime. The motivation behind ENTRUST is to ensure end-to-end trust management of medical devices including formally verified trust models, risk assessment process, secure lifecycle procedures, security policies, technical recommendations, and the first-ever real-time Conformity Certificates to safeguard connected medical devices.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
海外基金