Skip to content

Talks & Publications

Talks

Embedded Linux Security Exercised on the Secure Platform GyroidOS
Michael Weiß, Johannes Wiesböck, Felix Wruck, Maximilian Peisl, Fraunhofer AISEC
Class 2.4 at the embedded world Conference 2026, March 11, 2026, Nuremberg, Germany. The class shows how Linux can be used on embedded devices to comply with security-related certification requirements like IEC 62443 or Common Criteria — focusing on kernel mechanisms that protect the integrity of code and data, with practical insights based on GyroidOS.

Conference program (PDF)

Secure System-on-Chip: Protecting Operating Systems and Hardware
Interview with Dr. Michael Weiß, Fraunhofer AISEC
Published by FMD.insight (Research Fab Microelectronics Germany), December 15, 2025. The interview covers hardware-anchored platform security with GyroidOS — container isolation, TPM and OpenTitan trust anchors, RISC-V, and secure system-on-chip development for IoT and 6G.

Interview (English)   Interview (German)

Embedded Linux security exemplified on the secure platform GyroidOS
Felix Wruck, Fraunhofer AISEC
Security session at the OSADL Networking Day 2025, June 26, 2025, Heidelberg, Germany.

Event page

Embedded Linux Security
Michael Weiß, Johannes Wiesböck, Felix Wruck, Maximilian Peisl, Fraunhofer AISEC
Class 3.3 at the embedded world Conference 2025, March 11, 2025, Nuremberg, Germany. Hands-on class including Raspberry Pi exercises on secure boot, kernel integrity measurement (IMA) and full disk encryption with GyroidOS.

Class material & exercises   Conference program (PDF)

Publications

2025

Engine-Agnostic Evaluation of Container Isolation Characteristics
Felix Wruck, Maximilian Peisl, Michael Weiß
2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), IEEE, pp. 2894–2903

BibTeX
@inproceedings{Wruck_2025,
  title     = {Engine-Agnostic Evaluation of Container Isolation Characteristics},
  url       = {http://dx.doi.org/10.1109/Trustcom66490.2025.00343},
  DOI       = {10.1109/Trustcom66490.2025.00343},
  booktitle = {2025 IEEE 24th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom)},
  publisher = {IEEE},
  author    = {Wruck, Felix and Peisl, Maximilian and Wei{\ss}, Michael},
  year      = {2025},
  month     = nov,
  pages     = {2894--2903}
}

doi.org/10.1109/Trustcom66490.2025.00343

2024

HETCOM: Heterogeneous Container Migration Based on TEE- or TPM-established Trust
Felix Wruck, Maximilian Peisl, Christian Epple, Michael Weiß
Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems (CODASPY '24), ACM, pp. 51–60

BibTeX
@inproceedings{Wruck_2024,
  series    = {CODASPY '24},
  title     = {HETCOM: Heterogeneous Container Migration Based on TEE- or TPM-established Trust},
  url       = {http://dx.doi.org/10.1145/3643650.3658610},
  DOI       = {10.1145/3643650.3658610},
  booktitle = {Proceedings of the 2024 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems},
  publisher = {ACM},
  author    = {Wruck, Felix and Peisl, Maximilian and Epple, Christian and Wei{\ss}, Michael},
  year      = {2024},
  month     = jun,
  pages     = {51--60}
}

doi.org/10.1145/3643650.3658610

2022

GyroidOS: Packaging Linux with a Minimal Surface
Felix Wruck, Vasil Sarafov, Florian Jakobsmeier, Michael Weiß
Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems (CODASPY '22), ACM, pp. 87–96

BibTeX
@inproceedings{Wruck_2022,
  series    = {CODASPY '22},
  title     = {GyroidOS: Packaging Linux with a Minimal Surface},
  url       = {http://dx.doi.org/10.1145/3510547.3517917},
  DOI       = {10.1145/3510547.3517917},
  booktitle = {Proceedings of the 2022 ACM Workshop on Secure and Trustworthy Cyber-Physical Systems},
  publisher = {ACM},
  author    = {Wruck, Felix and Sarafov, Vasil and Jakobsmeier, Florian and Wei{\ss}, Michael},
  year      = {2022},
  month     = apr,
  pages     = {87--96}
}

doi.org/10.1145/3510547.3517917

2018

An Ecosystem and IoT Device Architecture for Building Trust in the Industrial Data Space
Gerd S. Brost, Manuel Huber, Michael Weiß, Mykolai Protsenko, Julian Schütte, Sascha Wessel
Proceedings of the 4th ACM Workshop on Cyber-Physical System Security (ASIA CCS '18), ACM, pp. 39–50

BibTeX
@inproceedings{Brost_2018,
  series    = {ASIA CCS '18},
  title     = {An Ecosystem and IoT Device Architecture for Building Trust in the Industrial Data Space},
  url       = {http://dx.doi.org/10.1145/3198458.3198459},
  DOI       = {10.1145/3198458.3198459},
  booktitle = {Proceedings of the 4th ACM Workshop on Cyber-Physical System Security},
  publisher = {ACM},
  author    = {Brost, Gerd S. and Huber, Manuel and Wei{\ss}, Michael and Protsenko, Mykolai and Sch{\"u}tte, Julian and Wessel, Sascha},
  year      = {2018},
  month     = may,
  pages     = {39--50}
}

doi.org/10.1145/3198458.3198459

2017

Freeze & Crypt: Linux Kernel Support for Main Memory Encryption
Manuel Huber, Julian Horsch, Junaid Ali, Sascha Wessel
Proceedings of the 14th International Joint Conference on e-Business and Telecommunications, SCITEPRESS, pp. 17–30

BibTeX
@inproceedings{Huber_2017,
  title     = {Freeze & Crypt: Linux Kernel Support for Main Memory Encryption},
  url       = {http://dx.doi.org/10.5220/0006378400170030},
  DOI       = {10.5220/0006378400170030},
  booktitle = {Proceedings of the 14th International Joint Conference on e-Business and Telecommunications},
  publisher = {SCITEPRESS - Science and Technology Publications},
  author    = {Huber, Manuel and Horsch, Julian and Ali, Junaid and Wessel, Sascha},
  year      = {2017},
  pages     = {17--30}
}

doi.org/10.5220/0006378400170030

2016

A Secure Architecture for Operating System-Level Virtualization on Mobile Devices
Manuel Huber, Julian Horsch, Michael Velten, Michael Weiß, Sascha Wessel
Information Security and Cryptology (ICISC 2015), Springer, pp. 430–450

BibTeX
@inbook{Huber_2016,
  title     = {A Secure Architecture for Operating System-Level Virtualization on Mobile Devices},
  ISBN      = {9783319388984},
  ISSN      = {1611-3349},
  url       = {http://dx.doi.org/10.1007/978-3-319-38898-4_25},
  DOI       = {10.1007/978-3-319-38898-4_25},
  booktitle = {Information Security and Cryptology},
  publisher = {Springer International Publishing},
  author    = {Huber, Manuel and Horsch, Julian and Velten, Michael and Weiss, Michael and Wessel, Sascha},
  year      = {2016},
  pages     = {430--450}
}

doi.org/10.1007/978-3-319-38898-4_25

2015

Improving mobile device security with operating system-level virtualization
Sascha Wessel, Manuel Huber, Frederic Stumpf, Claudia Eckert
Computers & Security, vol. 52, Elsevier, pp. 207–220

BibTeX
@article{Wessel_2015,
  title     = {Improving mobile device security with operating system-level virtualization},
  volume    = {52},
  ISSN      = {0167-4048},
  url       = {http://dx.doi.org/10.1016/j.cose.2015.02.005},
  DOI       = {10.1016/j.cose.2015.02.005},
  journal   = {Computers & Security},
  publisher = {Elsevier BV},
  author    = {Wessel, Sascha and Huber, Manuel and Stumpf, Frederic and Eckert, Claudia},
  year      = {2015},
  month     = jul,
  pages     = {207--220}
}

doi.org/10.1016/j.cose.2015.02.005

2013

Improving Mobile Device Security with Operating System-Level Virtualization
Sascha Wessel, Frederic Stumpf, Ilja Herdt, Claudia Eckert
Security and Privacy Protection in Information Processing Systems (IFIP SEC 2013), Springer, pp. 148–161

BibTeX
@inbook{Wessel_2013,
  title     = {Improving Mobile Device Security with Operating System-Level Virtualization},
  ISBN      = {9783642392184},
  ISSN      = {1868-422X},
  url       = {http://dx.doi.org/10.1007/978-3-642-39218-4_12},
  DOI       = {10.1007/978-3-642-39218-4_12},
  booktitle = {Security and Privacy Protection in Information Processing Systems},
  publisher = {Springer Berlin Heidelberg},
  author    = {Wessel, Sascha and Stumpf, Frederic and Herdt, Ilja and Eckert, Claudia},
  year      = {2013},
  pages     = {148--161}
}

doi.org/10.1007/978-3-642-39218-4_12