Skip to main content

DSI Publications

DSI Industrial & Policy Recommendations Series (IPR)

Recommendations for safety and IT security in medical devices

DSI Industrial & Policy Recommendations Series (IPR) 2017 (6)
Isabel Skierka (2017)
Subject(s)
Health and environment; Information technology and systems; Technology, R&D management
Keyword(s)
IT security, cybersecurity, e-health, IoT, safety, medical devices
The healthcare industry is undergoing great technological transformations. Hospitals are going digital and medical devices – whether implanted in patients’ bodies or stationed in hospitals – are equipped with increasing computing power and wireless connectivity. Connected healthcare can offer safer, more efficient, and timely medical service delivery. It also presents great economic opportunities – according to a Roland Berger consultancy firm study, the digital healthcare market is set to grow at average annual growth rates of 21 percent until 2020. Yet, the integration of computing and communication technologies in safety-critical medical systems will expose them to the same network and information security (cyber security) threats as other information technology (IT) systems. Research and real-world incidents have shown that IT security risks in healthcare are systemic. Cyber attacks’ impact on the privacy of patient data has already been established. More recently, their potential impact on patient health and safety has been raising concerns for healthcare organizations, regulators, and medical device manufacturers alike. The management and governance of related risks requires comprehensive standardization, regulation, and best practices to encompass both IT security and safety. DSI has analyzed the convergence of safety and security risks in healthcare and the Internet of Things through a review of the relevant literature, as well as expert interviews and a workshop with representatives from health organizations, medical device manufacturers, IT security experts, safety engineers, regulators, and certification bodies. On this basis, DSI has developed recommendations for policy and industry, which are presented by this paper after a short analysis of the current status of security in connected healthcare.
Volume
2017
Journal Article

Robust fuzzy extractors and helper data manipulation attacks revisited: Theory vs practice

IEEE Transactions on Dependable and Secure Computing PP (99): 1–14
Georg T. Becker (2017)
Subject(s)
Information technology and systems
Keyword(s)
Robust fuzzy extractor, physical unclonable functions (PUFs), helper data manipulation attacks
Volume
PP
Journal Pages
1–14
ISSN (Print)
1545-5971
Journal Article

IT-Sicherheitsrecht – Schutz kritischer Infrastrukturen und staatlicher IT-Systeme [IT security law – Protection of critical infrastructure and government ICT systems]

Computer und Recht 33 (10): 648–656
Martin Schallbruch (2017)
Subject(s)
Economics, politics and business environment; Information technology and systems; Technology, R&D management
Keyword(s)
IT security, cybersecurity, security law, network and information security, EU law, critical infrastructure protection, government ICT systems
Volume
33
Journal Pages
648–656
ISSN (Online)
2194-4172
Conference Proceeding

A fair and comprehensive large-scale analysis of oscillation-based PUFs for FPGAs

27th International Conference on Field Programmable Logic and Applications (FPL)
Alexander Wild, Georg T. Becker, Tim Gü­ney­su (2017)
Subject(s)
Technology, R&D management
Keyword(s)
Physical Unclonable Function (PUF), ring oscillator PUF, TERO PUF, loop PUF, Field Programmable Gate Array (FPGA)
DSI Industrial & Policy Recommendations Series (IPR)

Security record of open source and free software

DSI Industrial & Policy Recommendations Series (IPR) 2017 (5)
Martin Schallbruch (2017)
Subject(s)
Economics, politics and business environment; Information technology and systems; Technology, R&D management
Keyword(s)
Open source software, free software, IT security, cybersecurity
In April 2017, the Digital Society Institute hosted a workshop entitled "How secure is free software? Security record of open source and free software." The report summarizes the findings of the workshop and gives recommendations for companies and public agencies as well as policy recommendations.
Volume
2017
DSI Industrial & Policy Recommendations Series (IPR)

Recommendations for safety, security and data policy in automotive IT

DSI Industrial & Policy Recommendations Series (IPR) 2017 (4)
Sandro Gaycken, Martin Schallbruch, Georg T. Becker (2017)
Subject(s)
Technology, R&D management
Keyword(s)
Automotive IT, safety, security, data policy, vehicle safety
The DSI has carried out stakeholder workshops with the automotive sector, mobility digital startups, automotive insurers, and vehicle inspectors and, on this basis, has developed the recommendations for safety, security and data policy in automotive IT. The car of the future will collect a wide range of data. Ownership and usage of those data must be clarified, and legal and technical characteristics have to be established in order to endure data protection, data security, vehicle safety, and a fair market.
This issue contains German text and English translation in one file.
Volume
2017
Magazine article

On cyber attacks and the accidental war

Forbes India
Subject(s)
Technology, R&D management
Keyword(s)
cyber attacks, Internet, crime
Op-Ed

IT-Sicherheit: Bundestag verabschiedet NIS-Umsetzungsgesetz

CRonline
Martin Schallbruch (2017)
Subject(s)
Technology, R&D management
Report

Cybersecurity international: Unterschiedliche Prioritäten [International cybersecurity: Different priorities]

In Digitalpolitik: Eine Einführung, edited by Lorena Jaume-Palasí, Julia Pohle, Matthias Spielkamp, 19–26. Berlin: Wikimedia.
Isabel Skierka (2017)
Subject(s)
Information technology and systems
Keyword(s)
Cybersecurity, National Security, Human Rights, Conflicts
Secondary Title
Digitalpolitik: Eine Einführung
Pages
19–26
Report

The security of components: An evaluation of physical and logical attacks

NXP
This proprietary study was commissioned by NXP.
Sandro Gaycken, Georg T. Becker (2017)
Subject(s)
Technology, R&D management