Learn more about the security measures required for trust centers that automotive suppliers need in their manufacturing processes to encrypt control units.
Learn more about the security measures required for trust centers that automotive suppliers need in their manufacturing processes to encrypt control units.
Setting up an online trust center enables a German automotive supplier to perform various cryptographic operations via REST interfaces. These operations include, among other things, the generation of random numbers, the creation and management of cryptographic keys and certificates, and the digital signing of data. The Trust Center plays an important role in manufacturing within the automotive sector, particularly in the encryption of control units. However, it turned out that the TrustCenter’s internal access management system lacked certain features and that adding new functions was very costly and time-consuming.
To address these challenges, the customer sought a solution that would provide better security for the trust center, more precise access rights to cryptographic objects, and easier expandability of the overall system to include additional functionalities.
Following the requirements analysis, experts at CAS AG recommended a solution that uses IBM Datapower Gateway and IBM App Connect Enterprise as an additional access layer between the Online Trust Center and the REST clients. These two components are supplemented by a web-based application for configuring users and access rights. CAS’s proprietary monitoring solution, CASMON, handles transaction monitoring.
IBM Datapower serves as a security gateway to authenticate REST clients and protect against attacks such as DDoS. In conjunction with a custom-developed web application, IBM App Connect Enterprise handles the authorization of the REST clients. This web application allows you to configure individual users’ access rights to REST operations and crypto objects with a high degree of granularity. It also offers a role- and client-based model, a processing and approval workflow, and process automation through the Trust Center.
In addition, IBM App Connect Enterprise was used to implement many features that could not have been implemented in the Trust Center—or would have been very costly and time-consuming to do so.
With the solution it introduced, the automotive supplier has protected access to its online trust center against unauthorized access and attacks. The solution makes it easy to add new features without having to do so in the Trust Center. By using IBM App Connect Enterprise as an intermediary layer between the REST clients and the Trust Center, the existing online Trust Center can be easily replaced in the future with a solution from another provider. This transition is carried out transparently for clients using a stable REST interface, so no changes are required on the client side.
Setting up an online trust center enables a German automotive supplier to perform various cryptographic operations via REST interfaces. These operations include, among other things, the generation of random numbers, the creation and management of cryptographic keys and certificates, and the digital signing of data. The Trust Center plays an important role in manufacturing within the automotive sector, particularly in the encryption of control units. However, it turned out that the TrustCenter’s internal access management system lacked certain features and that adding new functions was very costly and time-consuming.
To address these challenges, the customer sought a solution that would provide better security for the trust center, more precise access rights to cryptographic objects, and easier expandability of the overall system to include additional functionalities.
Following the requirements analysis, experts at CAS AG recommended a solution that uses IBM Datapower Gateway and IBM App Connect Enterprise as an additional access layer between the Online Trust Center and the REST clients. These two components are supplemented by a web-based application for configuring users and access rights. CAS’s proprietary monitoring solution, CASMON, handles transaction monitoring.
IBM Datapower serves as a security gateway to authenticate REST clients and protect against attacks such as DDoS. In conjunction with a custom-developed web application, IBM App Connect Enterprise handles the authorization of the REST clients. This web application allows you to configure individual users’ access rights to REST operations and crypto objects with a high degree of granularity. It also offers a role- and client-based model, a processing and approval workflow, and process automation through the Trust Center.
In addition, IBM App Connect Enterprise was used to implement many features that could not have been implemented in the Trust Center—or would have been very costly and time-consuming to do so.
With the solution it introduced, the automotive supplier has protected access to its online trust center against unauthorized access and attacks. The solution makes it easy to add new features without having to do so in the Trust Center. By using IBM App Connect Enterprise as an intermediary layer between the REST clients and the Trust Center, the existing online Trust Center can be easily replaced in the future with a solution from another provider. This transition is carried out transparently for clients using a stable REST interface, so no changes are required on the client side.
Setting up an online trust center enables a German automotive supplier to perform various cryptographic operations via REST interfaces. These operations include, among other things, the generation of random numbers, the creation and management of cryptographic keys and certificates, and the digital signing of data. The Trust Center plays an important role in manufacturing within the automotive sector, particularly in the encryption of control units. However, it turned out that the TrustCenter’s internal access management system lacked certain features and that adding new functions was very costly and time-consuming.
To address these challenges, the customer sought a solution that would provide better security for the trust center, more precise access rights to cryptographic objects, and easier expandability of the overall system to include additional functionalities.
Following the requirements analysis, experts at CAS AG recommended a solution that uses IBM Datapower Gateway and IBM App Connect Enterprise as an additional access layer between the Online Trust Center and the REST clients. These two components are supplemented by a web-based application for configuring users and access rights. CAS’s proprietary monitoring solution, CASMON, handles transaction monitoring.
IBM Datapower serves as a security gateway to authenticate REST clients and protect against attacks such as DDoS. In conjunction with a custom-developed web application, IBM App Connect Enterprise handles the authorization of the REST clients. This web application allows you to configure individual users’ access rights to REST operations and crypto objects with a high degree of granularity. It also offers a role- and client-based model, a processing and approval workflow, and process automation through the Trust Center.
In addition, IBM App Connect Enterprise was used to implement many features that could not have been implemented in the Trust Center—or would have been very costly and time-consuming to do so.
With the solution it introduced, the automotive supplier has protected access to its online trust center against unauthorized access and attacks. The solution makes it easy to add new features without having to do so in the Trust Center. By using IBM App Connect Enterprise as an intermediary layer between the REST clients and the Trust Center, the existing online Trust Center can be easily replaced in the future with a solution from another provider. This transition is carried out transparently for clients using a stable REST interface, so no changes are required on the client side.

