Risk Assessment for Space Nanosatellites

Astrocast

CYSEC carried out a risk assessment of Astrocast’s existing architecture and redesigned the architecture for an end-to-end, secure IoT ecosystem.

EXEC. SUMMARY

INDUSTRY

Telecommunications

Size

60+

Business Challenge

Secure the end-to-end IoT communication ecosystem of 80 nanosatellites

Solution

CYSEC LAB security evaluation and architecture design services

Customer

astrocast

Astrocast is Switzerland’s first commercial satellite-telecom operator. In collaboration with European Space Agency, Airbus, and Thuraya, Astrocast is building a constellation of 80 nanosatellites with an objective to provide two-way IoT communications services at low cost.

Challenge

Astrocast required a secure-by-design approach to their product architecture; their business model depends on the security of their IoT ecosystem. Security needs to cover a vast system: a two-way chain of communication from the mission control center, via the satellites, to their client’s terminals.

Engagement

CYSEC-Case-Studies-2

Step 1

CYSEC LAB carried out a risk assessment of Astrocast’s complex product architecture, taking into account multiple ecosystem constraints. The team delivered a prioritized list of risks and a mitigation plan for each of them.

Step 2

Based on the threat model, risk analysis, and risk trade-off, CYSEC developed the architecture design for their security solution.

Outcome

Within 5 months, CYSEC had designed the security architecture. Security is thereby ensured end-to-end: from Astrocast’s customers, through the 80 nanosatellites of the constellation, all the way to the IoT terminals on ground and at sea.

Key management and the public safety sector

Protecting Intellectual Property

CYSEC enables Geosatis to secure communications for IoT-based electronic monitoring products with software & hardware-based key management and encryption.

EXEC. SUMMARY

INDUSTRY

Public safety

Size

50

Business Challenge

Get defense-in-depth IoT security for their products, with a software & hardware-based key management and encryption.

Solution

CYSEC ARCA appliance deployed on-premise and a custom CYSEC developed software deployed on top.

Customer

Geostatis logo

GEOSATIS is a Swiss-based global leader in electronic monitoring and predictive analytics solutions. The company offers technology for the supervision of parolees, probationers and defendants. It works with criminal justice agencies to enhance public safety, improve offender rehabilitation, and reduce recidivism.

Challenge

When GEOSATIS developed a new version of their IoT-based electronic monitoring product, they wanted to take their IoT security up a level with a defense-in-depth approach.

Solution

CYSEC provided a two-fold solution. The CYSEC ARCA Trusted OS appliance was deployed on-premise to secure containerized workloads. A custom-built software, developed by CYSEC and deployed on top of CYSEC ARCA, would facilitate straightforward key management of their IoT products.

CYSEC ARCA is used for the most sensitive parts of their products. The cryptographic API in ARCA is used to sign configuration files and firmware and to derive and generate keys for their IoT products.

Within a few months, the CYSEC ARCA lightweight appliance was deployed on-premise with the custom-built key management application deployed on top.

Outcome

GEOSATIS uses CYSEC ARCA to keep their line of products fully functional and to secure end-to-end communication between IoT products (such as bracelets, chargers, unlockers, beacons) and the backend. With CYSEC’s solution, GEOSATIS can securely perform firmware updates and IoT device provisioning using front-edge IoT security and key management technology, protecting Geosatis IP.

ClearSpace

ClearSpace-1 mission: preliminary architecture design of ground segment components.

Find out how ClearSpace benefited from the CYSEC LAB security architecture assessment and design services.

EXEC. SUMMARY

INDUSTRY

Aviation & Aerospace

Size

20

Business Challenge

Ground station secure architecture assessment and design for ClearSpace-1 mission

Solution

Services provided by CYSEC LAB

Customer

Clearspace logo

ClearSpace was founded out of the realization that On-Orbit Servicing and Space Debris Removal are vital services for the future of Space exploration and operations. In 2019, ClearSpace was selected by the European Space Agency to lead the first mission to remove debris from Orbit by 2025. ClearSpace has assembled a robust industrial team and is building up the path toward sustainable Space operations, starting with ClearSpace-1.

Challenge

ClearSpace is currently designing, developing and procuring a proprietary ground system infrastructure to support ClearSpace-1 and prepare for follow-on missions. ClearSpace requires a secure-by-design approach which identifies risks and embeds resilience from the start. ClearSpace, like many space companies, works with third party providers for some of its building blocks. Multilateral partnerships and consortia bring advantages while losing control over the chain of trust can introduce security risks. ClearSpace needed consultancy from a company with space ecosystem security experience to conduct a risk assessment of the design and assess the various industrial proposals from a security and architectural perspective.

Engagement

In a five-week period, CYSEC performed the following:

Outcomes

By providing a risk assessment and remediation measures, CYSEC is supporting ClearSpace towards its mission objective of safe active debris removal from space and prepare for a commercial service catalogue. Our work was efficient, enabling them to progress with the next stages of their project.

Penetration Testing Services for Fintech

Altcoinomy

CYSEC LAB provided advanced penetration testing services for Altcoinomy to identify and address vulnerabilities in an KYC/AML platform, to protect client data.

EXEC. SUMMARY

INDUSTRY

Fintech

Size

< 10

Business Challenge

Ensure their KYC/AML platform was secure before go-live

Solution

CYSEC LAB web-application penetration testing services

Customer

Altcoinomy is a Swiss-based fintech company that specializes in cryptocurrency due diligence and institutional trading. Altcoinomy operates an OTC trading desk where it gets clients best pricing on trades. A core part of their operations is the onboarding platform, an online KYC/AML platform facilitating the onboarding of participants in blockchain projects.

Challenge

Trust is a major growth driver in fintech. Applications need to be secure,
robustand available at all times or they risk losing credibility.
Prior to launching their KYC platform, Altcoinomy chose to test and
assess the security of its application and thus contacted the CYSEC LAB
for support.

Engagement

CYSEC security engineers performed a web-application penetration testing on the KYC platform within the staging environment.

Outcomes

CYSEC successfully identified security issues in the KYC platform and confirmed their remediation, thus eliminating the risks before the market launch.

Protecting Digital Assets

METACO’s SILO platform secured by ARCA

METACO relies on ARCA Trusted OS to secure sensitive data in SILO,
a technology stack for managing cryptocurrencies, tokens, and distributed ledgers.

EXEC. SUMMARY

INDUSTRY

Fintech

Size

30+

Business Challenge

Secure highly sensitive data with a partner that provides the secure hardware element of SILO platform

Solution

SILO (based on CYSEC ARCA)

Customer

Since 2014, the Swiss-based fintech company, METACO, has been helping banks and financial institutions securely enter the digital asset management market and capitalise on the latest blockchain technologies and systems. At the heart of their operations is the SILO platform, a technology stack for managing cryptocurrencies, tokens, and distributed legers.

Challenge

The success of METACO depends on its ongoing ability to secure the highly sensitive data that it manages. They wanted to partner with a company who would help them provide secure hardware technology to secure data in all its states, against all types of cyber-attacks.

Solution

METACO’s Digital Asset Management and trading platform runs on top the CYSEC ARCA confidential computing environment. As a trusted execution environment (TEE), CYSEC ARCA provides optimal protection for high-value data in all its states and can be deployed on-premise or accessed in the cloud.

Engagement

Step 1

In a series of technology workshops, a joint solution was designed that included the customization of CYSEC ARCA to METACO’s specific requirements

Step 2

Within a short timeframe, CYSEC and METACO developed and delivered an application for the financial services industry, built on CYSEC’s technology and METACO’s digital asset management platform, SILO

Outcomes