Fraunhofer AISEC and IOSB are Security Partners for Secure Data Exchange in the Semiconductor-X Project
In the Semiconductor-X project, funded by the German Federal Ministry for Economic Affairs and Energy (BMWE), an industry consortium led by Intel, Infineon, Siemens, SAP, and Bosch is developing a joint data room infrastructure for semiconductor manufacturing by September. The Fraunhofer Institute for Applied and Integrated Security AISEC and the Fraunhofer Institute for Optronics, System Technologies and Image Exploitation IOSB have now joined the consortium as cybersecurity partners and are developing a roadmap for secure data rooms. The goal is to enable companies to securely exchange sensitive production and process data along the value chain. The results are also intended to support other Manufacturing-X initiatives.
Industrial companies are connecting machines, locations, and partners along value chains, but cybersecurity often lags behind. This is precisely the challenge facing the Manufacturing-X projects that emerged from Gaia-X. One example is the Semiconductor-X project: It aims to enable participating companies in the value chain to exchange sustainability, production, or process data securely and reliably via a data room.
CRA and NIS-2: Roadmap for Secure Industrial Data Rooms
Since the roles of companies and the interests to be protected vary greatly depending on the type of data, the respective data owners should be able to establish and monitor the rules governing the use of the data. For this reason, machine-readable data usage agreements form the basis for data exchange. It is essential to enforce these agreements with technical actions to provide appropriate security guarantees. Particularly when dealing with highly sensitive data, this requires advanced security mechanisms, such as securing the software stacks used by means of trusted and confidential computing.
The European legal framework also calls for a proactive and risk-based approach to cybersecurity. The Cyber Resilience Act (CRA) imposes mandatory requirements on manufacturers and developers of connectors or gateways, while the NIS-2 Directive sets mandatory requirements for operators of federated services or hosted connectors. Together with existing Semiconductor-X partners, researchers at Fraunhofer AISEC and IOSB are developing a roadmap for secure industrial data rooms. To this end, they are particularly identifying vulnerabilities and blind spots that still have to be closed for industrial use.
The researchers are also developing specifications for data room gateways to process data of varying criticality levels, as well as concepts for data room governance, such as processes for onboarding data room participants and certifying them. Other key areas of focus include guidelines for the secure development and operation of components and services. The goal is to produce context-independent results to enable direct transfer to other Manufacturing-X contexts. This provides companies with practical guidance on how to securely set up their digital ecosystems from the very beginning.
Last modified:
Fraunhofer Institute of Optronics, System Technologies and Image Exploitation IOSB