Periodic Reporting for period 1 - ENTRUST (ENsuring Secure and Safe CMD Design with Zero TRUST Principles)
Okres sprawozdawczy: 2023-01-01 do 2024-06-30
1- ENTRUST Architecture Finalization: The architecture was successfully designed, establishing a holistic security model covering the entire CMD lifecycle. This was achieved through collaborative design and stakeholder input.
2- Risk Assessment and Threat Modelling: The Risk Assessment component, calculating Required Trust Levels (RTL), and the Threat Modelling component, using Large Language Models (LLMs) to identify threats, were completed. These were developed through research and testing, allowing real-time security adjustments.
3- Formal and Software Verification Tools: Tools for ‘security-by-design’ Formal Verification and Software Verification, including fuzzing techniques, were created to detect and address vulnerabilities early. These ensure CMDs meet security standards from design to deployment.
4- Digital Twin and Secure Updates: A Digital Twin was implemented for attack emulation, alongside secure software update mechanisms. These were developed to test and mitigate cyberattacks in a simulated environment, ensuring device integrity.
5- Open-Source Roadmap: An open-source roadmap for CMD Trust Reference Implementation was established, fostering collaboration on platforms like GitHub and Zenodo, with support from partners like OpenContinuum and ECLIPSE.
ENTRUST is also developing an open-source roadmap for the CMD Trust Reference Implementation, fostering a collaborative ecosystem for secure medical devices. This initiative, supported by platforms like GitHub and Zenodo, emphasizes community involvement to enhance the platform's quality, adoption, and sustainability. The plan includes a Minimum Viable Product (MVP) and Open-Source Development (OSD) strategy, with support from the OpenContinuum action and ECLIPSE collaboration.
To ensure successful adoption and enhance security and trustworthiness of connected medical devices worldwide, ENTRUST needs to focus on:
-Ongoing R&D to refine threat detection, risk assessment, and secure device lifecycle management.
-Demonstrations and pilot projects to validate the framework in real-world settings.
-Market access strategies to position ENTRUST within the growing medical device and cybersecurity sectors.
-Effective management of intellectual property rights and collaboration with open-source initiatives.
-Alignment with regulatory and standardization frameworks to ensure compliance and facilitate market adoption.
-Internationalization to expand the project’s global reach and ensure alignment with international standards.