Our client, a specialist in high-voltage control systems for the energy and defense sectors, needed to modernize its equipment to meet stringent safety standards. This project involved migrating a new hardware architecture to an NXP Layerscape processor while drastically improving the security of their Yocto Linux distribution in preparation for major certifications.
To respect professional secrecy and confidentiality agreements, the identity of our clients and certain technical details are intentionally anonymized. We primarily work on strategic, high-value-added innovation projects, for which discretion is essential to preserving our clients' competitive advantage.
The mission presented major technical challenges spread across two distinct aspects.
From a software perspective, the main challenge lay in modernizing a business application to fully integrate the recommendations of ANSSI.
Initially, it was necessary to modify the permissions of the old application to prevent it from running with root privileges, taking into account all critical dependencies. The next step involved integrating the IEC 62351-8 standard (a centralized role-based authentication system).
The ultimate goal, which is very ambitious, is to bring a system to level 3 of the IEC 62443 safety standard, a strong market requirement.
On the hardware side, efforts focused on resolving complex integration issues encountered on new cards. The teams specifically addressed the configuration of the Device Tree and U-Boot, a crucial step in correcting PCIe interface errors and stabilizing the hardware.
+20
years of age
1 month
overhaul
To address these challenges, Smile intervened at the heart of our client's R&D team to carry out a series of strategic actions.
The intervention began with BSP porting and Yocto integration, which allowed for the adaptation of the U-Boot boot process and the creation of custom configurations and Device Trees for a board built around an NXP LS1028A processor. In parallel, a major effort was made to harden cybersecurity by strengthening the Linux kernel for ARM64 and x86_32 architectures, complemented by the design of a Bash script for the system firewall to strictly adhere to the ANSSI recommendations.
The teams also took charge of developing centralized authentication, designing and developing a robust C++ system that leverages PAM integration and an LDAP server. To structure access, the implementation of a Restricted Access Control (RBAC) system allowed for restricting and segmenting rights for business applications and the API. Finally, the project encompassed network maintenance and upgrades, including the development of an SNMP extension and the maintenance of the existing C++ code.
Thanks to this intervention, our client now has a robustly secured Linux distribution based on Yocto, having reached the first level of compliance with ANSSI recommendations. The newly implemented centralized authentication system offers much more flexible management of access rights on critical hardware. These technical foundations now allow our client to confidently pursue the highest-level cybersecurity certifications required by its own customers and partners.
This project required a rare combination of expertise: BSP migration to Yocto and compliance with ANSSI standards. We successfully pivoted a legacy application to the highest cybersecurity standards, without compromising its field reliability.
Cédric Garel
Industrial & Product Systems Manager, Smile, Nantes