Our L4Re Operating System Framework is running in many applications, from automotive to smart home devices.
The independent, family-owned company from Cologne, Germany, founded in 1974, has been a cyber security specialist in the IT sector for almost 50 years. As a consultant to the public sector and in the area of critical infrastructures, infodas is one of the most senior companies in the IT security industry with extensive experience.
infodas develops the most advanced cross domain solutions based on security-by-design principles that enable digitization of formerly air-gapped domains with classified information. The SDoT product family cross domain solutions (SDoT Security Gateway, SDoT Diode, SDoT Labelling Service, PATCH.works) are approved up to German, EU, NATO SECRET and are listed in the NATO information assurance product catalogue. The SDoT Security Gateway also has a CC EAL4+ certification.
The SDoT product family is based on the L4Re operating system.
For more information visit the infodas website.
For the development of the SDoT product family, Kernkonzept provided its open source operating system L4Re as a basis. In close consultation and support during the selection and design of the hardware, Kernkonzept first developed the requirements for the system architecture together with infodas and then implemented them.
Implementation took place in close cooperation with BSI. Since 2016, all products in the SDoT range have received BSI secret protection approval. Several new products such as the SDoT Gateway Express were developed on the basis of L4Re.
L4Re allows to consolidate applications that previously required separate hardware to implement securely onto one piece of hardware and separate them just as securely. This saves space and energy, enabling the use of these systems in space-constrained environments like vehicles, aircraft etc.
Kernkonzept and infodas have developed a secure platform whose separation is just as secure as a physical separation. With the L4Re operating system, all necessary applications can run on one server, but remain reliably separated.
As part of the platform, the L4Re separation kernel helps to meet all BSI security requirements and ensures that all products in the SDoT line meet the secrecy approval for the public sector and the KRITIS area.
As a provider of innovative cybersecurity solutions for the public sector and the KRITIS area, it is essential for infodas to meet the requirements set by the BSI. With the L4Re system Kernkonzept provides the secure execution platform for infodas according to the “separation kernel” requirements profile.
Every customer gets a personal Customer Engineer Specialist assigned who accompanies you throughout the whole product life cycle.
genua GmbH, headquartered in Kirchheim near Munich, has specialized in IT security since 1992. It offers mobile security solutions, high-security gateways, VPN systems, and other software products.
genua is currently one of the leading providers of IT security and system management with several locations in Germany. Software solutions from genua are used worldwide by companies (including MAN, MTU Aero Engines, Würth Group, IVBB) and organizations with security tasks.
genua’s first own product line was genugate, launched in 1997. To this day, this firewall is the only one in the world with a classification as “highly resistant” and an EAL4+ certification according to the CC standard of the BSI.
In developing security solutions like the cyber-top and vs-top security laptops or the cyber-diode and vs-diode data diodes, genua relies on the open source software L4Re, which ensures strict separation of internal areas at the microkernel level.
Among other things, L4Re runs transparently in the background on the vs-top and creates isolated compartments for the security systems and the working environments, each of which has its own operating system. Exclusive allocation of hardware resources avoids dependencies. Attacks by malware or hacking remain limited to a working environment and cannot reach the security systems.
Data transfer from networks with a low security level (so-called black networks) to networks with a SECRET classification (so-called red networks) is particularly critical, for example when sending e-mails, transferring video data or patterns for virus protection software. For this purpose, genua has developed vs-diode together with Kernkonzept. This software makes it possible to run black and red networks together on the same hardware.
The vs-diode consists of two application level gateways (ALG), which communicate using TCP/UDP, and a one-way middle part. An L4Re microkernel ensures reliable separation of the two networks.
Thanks to L4Re’s highly secure microkernel technology, the vs-top 1.5 security laptop has received BSI approval for the classification level “VS – For official use only” (VS-NFD). This means that the laptop can also be used on the move; confidentially classified data can be processed and transferred via an encrypted connection. The high level of security is still linked to the familiar Windows working environment, offering both high usability and security.
The vs-diode also has BSI approval for NATO SECRET and EU SECRET classification levels.
During the development of the vs-top security laptop and vs diode, we actively consulted our partners in the design of the system architecture, so that our L4Re software could be properly set up. Our system engineers were engaged in the software development process.
As in all our projects, we assigned a dedicated employee to work with a project engineer at genua to keep a close connection for fast and effective results. We also provide security patches and on-site support for the security products we have developed with genua.
Every customer is being allocated with his personal Customer Contact Engineer who acts as personal reference person.
Elektrobit is an award-winning and visionary global vendor of embedded and connected software products and services for the automotive industry. A leader in automotive software with over 35 years serving the industry, Elektrobit’s software powers over five billion devices in more than 600 million vehicles and offers flexible, innovative solutions for car infrastructure software, connectivity & security, automated driving and related tools, and user experience. Elektrobit is a wholly-owned, independently-operated subsidiary of Continental.
Headquartered in Erlangen, Germany, Elektrobit has 24 offices in 11 countries with customers including 10 of the largest OEMs. Their flexible, innovative vehicle infrastructure software solutions deliver connectivity and safety, simplify autonomous driving and maximize usability.
For 35 years Elektrobit has been providing automotive software, making the company a respected industry leader. Today, Elektrobit software products control more than 5 billion devices in more than 600 million vehicles. Flexible, innovative vehicle infrastructure software solutions deliver connectivity and safety, simplify autonomous driving, and maximize usability.
Elektrobit’s Corbos Hypervisor is a bare-metal hypervisor for automotive E/E systems. Based on the microkernel-based L4Re operating system by Kernkonzept, it provides a virtualization environment where multiple guest operating systems can run on a single CPU.
What sets EB Corbos Hypervisor apart from other solutions is its unique safety and security properties.
The capability mangement locks the IPC relations between client and server inside the microkernel, while the servers reside outside the kernel space. For more information, visit Elektrobit.
The L4Re microkernel with its minimal trusted computing base allows the processing of functionalities in non-privileged mode, creating a secure software environment for applications in automated driving. Major parts of EB corbos Hypervisor are available as open-source software, as it is based on L4Re.
The L4Re microkernel provides the spatial and temporal isolation of these virtual machines, supporting security-critical, safety-related, and real-time applications by allowing parallel execution of native applications and guest operating systems.
We guide and support many of our customers during the complete life-cycle of their product. Our service range from individual consulting and software development to longterm support and trainings.
Every customer is being allocated with his personal Customer Contact Engineer who acts as personal reference person.
After the Internet first connected computers and then people, the hour has now come for the “Internet of Things”. More and more devices are networked and can be controlled, operated and maintained remotely.
The kitchen is an interesting application area for smart home technology. Here, too, in addition to reliability and security, the protection of connected devices is a high priority; after all, the stove or refrigerator should only be able to be controlled remotely by its owner, and in the event of errors, the manufacturer must be notified quickly so that updates and patches can be applied “over the air.”
For this reason, Kernkonzept was approached by manufacturer Electrolux. The global manufacturer of kitchen appliances for private households and large customers such as restaurants and industrial kitchens primarily offers complete solutions and is known for the high energy efficiency of its appliances. In addition to the Electrolux brand, AEG and Zanussi are also well-known brands in the German market.
For the Steampro steam oven, which can be accessed via WLAN, we developed the reliable and secure control unit based on our open source security software L4Re. Hardware and software were developed together to follow our principle of “security by design”. In addition to the L4Re components, we also developed the board support package, the system architecture and necessary drivers for Linux.
To adjust the temperature or stop the cooking process, Steampro owners don’t need to be in the kitchen, but can control the steam oven via an app or by voice thanks to secure Wifi networking. With our reliable software that both fends off external attacks and prevents cross-app malfunctions, Electrolux safeguards the functioning of its steam oven for years to come.
We accompanied Electrolux over the complete life cycle of their product. Following the individual consulting regarding hardware/software co-design and hardware selection for our L4Re operating system, our engineers developed the system architecture and BSPs as well as the necessary L4Re components for the Electrolux steam oven. After the time-to-market we offered onsite support and maintenance services for our software.
Every customer is being allocated with his personal Customer Contact Engineer who acts as personal reference person.
Airbus is a leading global manufacturer in aeronautics, space, and related services with around 135.000 employees. While being known for the biggest range of passenger airliners, Airbus has been a reliable partner to the EU, NATO and the associated countries of the western world for combat, transport, and mission aircrafts.
The company’s world-class portfolio of products includes the Eurofighter Typhoon swing-role combat aircraft; the A400M, C295 and CN235 airlifters; the A330 Multi-Role Tanker Transport; along with robust, dependable unmanned aerial systems (UAS).
Airbus also combines more than 50 years of field-proven technology with next-generation systems-of-systems architecture to ensure information superiority across the five operational domains: land, air, sea, space and cyber.
Airbus know-how is underscored by its prime contractor role for Europe’s Future Combat Air System (FCAS) – a network of manned and unmanned platforms from fighter and drones to satellites. As a key player Airbus provides Command and Control elements for NATO and other multinational frameworks.
With various partners, Airbus Defence and Space develops flexible and cyber resilient architectures and solutions, following the system of systems philosophy: pooling the resources of capabilities of several dedicated systems to create a new system that is essentially doing more than the sum of its parts.
For defence organizations it is essential to protect their critical data. A robust protection system is needed to ensure a secure bi-directional data exchange between allies, services, military and civilian systems. It is also vital that the exchange works reliably and securely between different sensitivity levels.
The Secure Gateway Exchange (SEG) by Airbus Defence and Space Cyber provides such a solution. For varying connection scenarios data can be filtered (structured or unstructured) and security-marked for different classification levels, while security domain separation is ensured. Confidential communications remain just that.
FCAS is the most important European defense project of the next decades. It will integrate the best expertise of various European partners in manned and unmanned aircraft, space and intelligence and become the next project in a long line of cutting-edge technologies we have pioneered.
FCAS is more than a new fighter. FCAS is a network-based, information collaborative combat system with fighters teaming with unmanned drones, called Remote Carriers, orchestrated through a Combat Cloud. One aspect which sets this initiative apart is the focus on non-traditional players (NTP), meaning companies and agencies from areas other than defence.
Kernkonzept was chosen along with several other German tech startups, SME, and research institutes to contribute to the FCAS programme. With a lot of expertise in autonomous driving, urban air mobility, AI, and alternative powered aviation, FCAS is supposed to profit from the full spectrum of German technology.
The results of the NTP initiative were implemented into software and hardware demonstrators for the FCAS, such as AI supported mission planning, certifiable cloud kernels, an unmanned aircraft launcher for transport aircrafts, or autonomous path finding and voice-controlled drones.
The next step, FCAS Demonstrator Phase 1B, was launched in 2022 and will see further work on the FCAS components in the next 3 years.
The L4Re Operating System Framework was used to develop a high-security hypervisor providing highly protected data connectivity between multiple airborne platforms. This was proven in two flight tests onboard an A400M aircraft in November 2021 and December 2022.
The secure combat cloud demonstrator showed that it is possible to transfer a secure operating system into an airborne cloud environment.
We guide and support many of our customers during the complete lifecycle of their product. Our service ranges from individual consulting and software development to longterm support and trainings.
Every customer is being allocated with his personal Customer Contact Engineer who acts as exclusive reference person.
JOYNEXT GmbH is a subsidiary of the Chinese company Ningbo Joyson Electronic Corp., headquartered in Ningbo, China. It specializes in the development of smart connectivity solutions for the automotive industry.
Around 1,500 people work for JOYNEXT worldwide, including in Dresden. For more than 20 years, JOYNEXT has been a Tier 1 supplier to the automotive industry (including brands like Volkswagen, Ford and Audi). It primarily offers solutions for autonomous driving, but also develops infotainment systems, telematics systems and connectivity solutions, both cloud-based and SaaS.
For more information, visit the JOYNEXT website.
Since May 2022, we have been supporting the JOYNEXT branch in Dresden with our deep know-how in operating systems, joining forces with the JOYNEXT software engineers to analyze, stabilize and optimize their infotainment systems based on the open-source Linux OS.
Our highly skilled developers fix relevant bugs in the BSP and the operating system-related software layers. We also have implemented cross-sectional functions for JOYNEXT.
We guide and support many of our customers over a long time. Our service for JOYNEXT ranges from individual consulting and software development to long term support and trainings.
Every customer is being allocated with his personal Customer Contact Engineer who acts as personal reference person.