Wind River Studio Linux Services: Lifecycle Performance Assurance

Wind River Studio Linux Services: 
Lifecycle Performance Assurance

Wind River offers lifecycle management services for Linux platforms and board support packages for your embedded systems project.

 

As projects mature, it can become challenging to continuously invest in the resources needed to keep software up to date. Wind River® offers full lifecycle management of your Yocto Project–based embedded Linux platform.

Our team of experts can take on the ongoing responsibility of monitoring, mitigating, and managing common vulnerabilities exposures, license compliance, and software defects as they emerge. We provide the technical solutions and support you need to help you keep your software current, secure, and stable throughout the life of your device. We are committed to making our customers successful.

What We Deliver

CONTINUOUS SECURITY MONITORING

We provide continuous and proactive monitoring of the health of your embedded Linux platform and BSP with timely alerts to new Common Vulnerabilities and Exposures (CVEs) as they emerge. We run your code through our professional grade scanner and compare it to our extensive database to accurately identify potential vulnerabilities.

  • On-demand scans of your Linux platform comprising your kernel, BSP, and shared and user libraries
  • Curated knowledge base of vulnerabilities and IP license compliance issues built from public sources such as NIST, the Yocto Project, and the MITRE database of CVEs
  • Deep analysis by Wind River engineers of the true impact on your platform
  • Detailed security report identifying all the CVEs that are open against your Linux platform

LICENSE USE IDENTIFICATION

Scan your embedded Linux platform and BSP to provide a detailed report of all the licenses used in your platform.

  • Ability to scan for all licenses used in your platform and categorize based on their permissiveness, copyleft, compatibility, and transitive dependencies
  • Detailed report identifying all the licenses used in your Linux Platform
  • License remediation implementation services available to address license compliance issues

COLLABORATIVE TRIAGE AND ASSESSMENT

Work with our team to quickly identify and prioritize the vulnerabilities based on a common vulnerability threshold (CVSS), severity of impact, and difficulty of attack and avoid ability. We work with you to build release plans to address critical and prioritized CVEs and defects.

  • Detailed security report identifying CVEs open against your platform
  • Fixes for newly identified critical and high CVEs at a CVSSv3 threshold of 7 and above
  • Online support portal for customers to request fixes for non-critical CVEs (CVSSv3 7)
  • Request review by Wind River engineers, with timely response
  • Premium Support options for customers needing dedicated engineers well versed in their project

CVE MITIGATION

Our team of engineers performs a deep analysis to determine the impact of the CVE on your Linux platform. We work with you to prioritize remediation options and timing. We backport, validate, and verify community-based patches before we apply them to your code. If a community solution is unavailable, we work with your engineering team to architect a technical solution.

  • Fixes for critical and high CVEs at CVSSv3 threshold 7 and above
  • Collaboration and prioritization of medium and low CVEs
  • Emergency patches to fix critical CVEs
  • Quarterly patches to fix other prioritized CVEs
  • Remediation packages available to help catch up on CVE technical debt

DEFECT REMEDIATION

Our team of skilled engineers provide technical fixes to defects. After remediation of the defect, we work with your team to revalidate the platform and assist with field updates.

  • Online portal for customers to submit defects
  • Collaborative prioritization of defects impacting your Linux platform and BSP
  • Emergency patches to fix your critical defects and quarterly patches to fix your prioritized defects

QUALITY WITH FOCUS ON YOUR HARDWARE

We ensure you have a high-quality and stable embedded Linux platform and BSP for your hardware. All remediation efforts enter the Wind River continuous integration (CI) pipeline for nightly, weekly, and monthly build and test processes. After remediation, testing, and release, Wind River will generate a new software bill of materials and documentation that can be used for project verification.

  • All modifications to your platform through patches or custom engineering validated and verified before redeployment
  • Hardware set up in our board farm and used by our CI pipeline to continuously test modifications to the platform
  • Nightly builds and test process leveraging the Wind River CI pipeline to ensure high quality
  • Emergency patches to fix your critical issues and quarterly patches to fix other issues

SOFTWARE BILL OF MATERIALS & RELEASE DOCUMENTATION

A new software bill of materials is generated after every code modification.

  • Online release dashboards and reports to track fixes and progress
  • Release notes to capture the CVEs and defects fixed in a release

COMMUNITY UPSTREAM

Wind River can be your partner and voice for the Yocto Project.
We can work on your behalf to upstream and contribute any fixes or engineered resolutions back to the community.

GLOBAL SUPPORT

Wind River has a global team of experts to support your Linux platform. Additional support options are available.
» See Awards and Industry Recognition for Wind River

  • Online support portal to submit tickets during the remediation period
  • Review by Wind River engineers to ensure timely response
  • Premium Support options for customers needing dedicated engineers well versed in their project

GLOBAL SUPPORT CENTERS

  • North America
  • Ottawa, Canada
  • Dublin, OH
  • Alameda, CA
  • Detroit, MI
  • Costa Rica
  • South America
  • Cordoba, Argentina
  • (C/E Services Only)
  • Europe
  • Stockholm, Sweden
  • Paris, France
  • Munich, Germany
  • Galati, Romania
  • China
  • Chengdu, China
  • Beijing, China
  • Korea
  • Seoul, Korea
  • Japan
  • Tokyo, Japan

OPEN SOURCE LEADERSHIP AND ENGINEERING EXPERTISE

Wind River is a founding member of the Linux Foundation’s Yocto Project. We are one of the top contributors and maintainers of several key components.
» Learn about the Yocto Project

  • Leading commercial contributor with commits to the Yocto Project for the last five years
  • Recent contribution of a security response tool
  • Proven project governance and advocacy within the community

FEATURED Blog

From Prototype to Post-Deployment: Linux Decision Points

In the embedded industry, the lifecycle of a Linux product can last 5, 10, or even 15 years or more, so the decisions you make now and along the way will impact speed, quality, and resources for years to come. They can also create technical debt and directly impact future scalability, profitability, and the overall success of your project.

≫ Read More

Wind River Studio Linux Services: Lifecycle Security

Wind River Studio Linux Services: 
Lifecycle Security

Wind River offers ongoing CVE monitoring, mitigation, and management of your Linux platform throughout the software development and deployment lifecycle.

 

Securing your embedded Linux platform is a full lifecycle responsibility. Ongoing monitoring and mitigation of known vulnerabilities impacting your project requires engineering resource investment, from development to deployment and throughout operational lifetime.

Scanning code for CVEs and license compliance issues can help identify risks before they become a liability. Critical and high-risk vulnerabilities impacting your code must be remediated. And, because new vulnerabilities are identified every day, ongoing CVE monitoring, prioritization, and mitigation is required. Wind River® delivers ongoing monitoring, mitigation, and management of Common Vulnerabilities and Exposures (CVEs) for your embedded Linux platform throughout the software development and deployment lifecycle.

What We Deliver

CONTINUOUS SECURITY MONITORING

We provide continuous and proactive monitoring of the health of your embedded Linux platform with timely alerts to new CVEs as they emerge. Leverage our curated knowledge base of CVEs built from public sources such as NIST, the Yocto Project, and the MITRE database of CVEs.

  • Full scan of your platform, comparison to our extensive database to accurately identify potential vulnerabilities, and deep analysis by our engineers of the true impact on your platform
  • On-demand scans of your Linux platform comprising your kernel, BSP, and shared and user libraries
  • Detailed security report identifying all the CVEs that are open against your Linux platform

LICENSE USE IDENTIFICATION

Scan your Linux platform to provide a detailed report of all the licenses used in your platform as well as transitive dependencies.

  • On-demand scans of your Linux platform comprising your kernel, BSP, and shared and user libraries
  • Ability to scan for all licenses used in your platform and categorize based on their permissiveness, copyleft, compatibility, and transitive dependencies
  • Detailed license report identifying all the licenses used in your embedded Linux Platform
  • Implementation services available to assist with license compliance remediation

COLLABORATIVE TRIAGE AND ASSESSMENT

Work with our team to quickly identify and prioritize vulnerabilities based on a common vulnerability threshold (CVSS), severity of impact, and difficulty of attack and avoid ability. We work with you to build release plans to address critical and prioritized CVEs.

  • Detailed security report identifying CVEs open against your platform
  • Fixes for newly identified critical and high CVEs at a CVSSv3 threshold of 7 and above
  • Online support portal for customers to request fixes for non-critical CVEs (CVSSv3 7)
  • Request review by Wind River engineers, with timely response
  • Premium Support options for customers needing dedicated engineers well versed in their project

CVE MITIGATION

Our team of engineers performs a deep analysis to determine the impact of the CVE on your Linux platform. We work with you to prioritize remediation options and timing. We backport, validate, and verify community-based patches before we apply them to your code. If a community solution is unavailable, we work with your engineering team to architect a technical solution.

  • Fixes for critical and high CVEs at CVSSv3 threshold 7 and above
  • Collaboration and prioritization of medium and low CVEs
  • Emergency patches to fix critical CVEs
  • Quarterly patches to fix other prioritized CVEs
  • Remediation packages available to help catch up on CVE technical debt

FOCUS ON QUALITY

We ensure you have a high-quality and stable Linux platform, and all remediation efforts enter the Wind River continuous integration (CI) pipeline for a nightly/weekly/monthly build and test process throughout development. After remediation testing and release, Wind River will generate a new software bill of materials and documentation that can be used for project verification.

  • All modifications to your platform through patches or custom engineering validated and verified before redeployment
  • Nightly builds and test process leveraging the Wind River CI pipeline to ensure high quality
  • Emergency patches to fix your critical CVEs and quarterly patches to fix other CVEs

SOFTWARE BILL OF MATERIALS & RELEASE DOCUMENTATION

A new software bill of materials is generated after every code modification.

  • Online release dashboards and reports to track fixes and progress
  • Release notes to capture the CVEs fixed in a release

COMMUNITY UPSTREAM

Wind River can be your partner and voice for the Yocto Project.
We can work on your behalf to upstream and contribute any fixes or engineered resolutions back to the community.

GLOBAL SUPPORT

Wind River has a global team of experts to support your Linux platform. Additional support options are available.
» See Awards and Industry Recognition for Wind River

  • Online support portal to submit tickets during the remediation period
  • Review by Wind River engineers to ensure timely response
  • Premium Support options for customers needing dedicated engineers well versed in their project

GLOBAL SUPPORT CENTERS

  • North America
  • Ottawa, Canada
  • Dublin, OH
  • Alameda, CA
  • Detroit, MI
  • Costa Rica
  • South America
  • Cordoba, Argentina
  • (C/E Services Only)
  • Europe
  • Stockholm, Sweden
  • Paris, France
  • Munich, Germany
  • Galati, Romania
  • China
  • Chengdu, China
  • Beijing, China
  • Korea
  • Seoul, Korea
  • Japan
  • Tokyo, Japan

OPEN SOURCE LEADERSHIP AND ENGINEERING EXPERTISE

Wind River is a founding member of the Linux Foundation’s Yocto Project. We are one of the top contributors and maintainers of several key components.
» Learn about the Yocto Project

  • Leading commercial contributor with commits to the Yocto Project for the last five years
  • Recent contribution of a security response tool
  • Proven project governance and advocacy within the community

FEATURED Blog

From Prototype to Post-Deployment: Linux Decision Points

In the embedded industry, the lifecycle of a Linux product can last 5, 10, or even 15 years or more, so the decisions you make now and along the way will impact speed, quality, and resources for years to come. They can also create technical debt and directly impact future scalability, profitability, and the overall success of your project.

≫ Read More

Cybersecurity and Containers in Intelligent Edge Avionics

play
CHOOSE-YOUR-OWN WEBINAR

   Cybersecurity and Containers  
  in Intelligent Edge Avionics
  

Modern avionics has brought software container technology to the intelligent edge for both commercial and military systems. With this comes the need for heightened cybersecurity protection.

Listen as Wind River® experts Paul Parkinson, director of field engineering for A&D, and Michel Chabroux, senior director of product management, discuss the use of containers in avionics systems and how the technology can provide cybersecurity. View the entire session above, or pick and choose the sections you’re most interested in below.

Paul Parkinson
Michel Chabroux

   Choose Your Chapters   

 
play Introduction

Intro & Avionics Container Demo

play Real Time OS Containers

Real-Time OS Containers

play Container Use for Avionics

Container Use for Avionics

play Security & Trust for Avionics

Security & Trust for Avionics

play Discover Performance

Discover Performance

play Key Questions

Key Questions

 
 

A New Approach to Purpose-Built Linux

play
CHOOSE-YOUR-OWN WEBINAR

  A New Approach  
   to Purpose-Built Linux
  

Embedded solution developers need a quick and easy purpose-built embedded Linux for their edge solutions — especially now, as the global embedded systems market is expected to grow at a CAGR of 5.5% by 2026 (Research and Markets).

Listen to Jay Kruemcke as he discusses the new Wind River® Linux binary distribution, a purpose-built Linux for the intelligent edge. View the entire session above, or pick and choose the sections you’re most interested in below.

Jay Kruemcke

   Choose Your Chapters   

 
play Market Landscape & Challenges

Market Landscape & Challenges

play Intro To Wind River Linux Binary Distribution

Intro to Wind River Linux Binary Distribution

play Wind River Linux Distro Deep Dive

Wind River Linux Distro Deep Dive

play Linux Assembly Tool:

Linux Assembly Tool

play Wind River Linux: Source vs. Binary

Wind River Linux: Source vs. Binary

play Executive Summary

Executive Summary

play 11 Key Questions Answered

11 Key Questions Answered

 
 

When You Need Simics for Your Digital Twin (And When You Don't)

play
CHOOSE-YOUR-OWN WEBINAR

   When You Need Simics  
  for Your Digital Twin (And When You Don’t)
  

Wind River® has helped customers simulate their systems for decades — long before the term "digital twin" was invented.

Join us for an exploration of why you might want to build a digital twin in the first place, and when Simics would and would not be useful. Watch the full webinar above, or check out a few of the highlights below.

   Sample Highlights   

 
play Lo-Fi Twins

Lo-Fi Twins

play Hi-Fi Twins

Hi-Fi Twins

play Mirroring the Real-Life Environment

Mirroring the Real-Life Environment

play Scope Creep

Scope Creep

play A Real-Life Example

A Real-Life Example

play Taking the Next Step

Taking the Next Step

 
 

Wind River Linux データシート - Japan


 

概要

Wind River® Linuxを利用することにより、高い堅牢性と高い信頼性を備えた、セキュアなLinuxベースの組込みデバイス・組込みシステムを構築することができます。ウインドリバーは、組込みLinuxの運用において大きな課題となるソフトウェアの不具合を追跡し、セキュリティパッチを適用することにより、お客様のコードベースを最適な状態に維持できます。自社でRYO(Roll-your-Own)を維持する場合に発生するリスクや開発工数を削減可能です。さらには、市場からの厳しい要求仕様や、認証に準拠したランタイムのカスタマイズ、IP(知的財産)および輸出におけるコンプライアンスの遵守にも対応し、お客様の製品開発コストを大幅に削減します。

優れた機能

  • 高い堅牢性と高い信頼性を備えた、セキュアなエッジデバイスやエッジシステムをRYO(Roll-your-Own)のリスクなく、構築可能です
  • 市場投入までの期間を短縮し、TCOを削減。オープンソフトウェアによるメリットを最大限に活かすことができます
  • デバイスに統合されたIP(知的財産)のロイヤリティやサブスクリプションの制約を解消することができます
  • 完全なオープンソース製品であり、Yocto Projectと互換性のあるツールで開発可能です
  • ディスクやメモリの消費量を大幅に削減。リアルタイム性(preempt_rt)や高可用性で動作するLinuxへとカスタマイズできます
  • ウインドリバーがすべてのパッケージについて、コンテンツ、著作権、ライセンスに関する完全な情報を提供します。法的な責任やコンプライアンスに関する問題を回避することができます

カスタマーサポート

Wind River Linuxは、受賞歴のあるサポート体制をグローバルに有し、複数のタイムゾーンでのお客様のソフトウェア開発を支援します。

詳細は以下をご参照ください。www.windriver.com/japan/services

プロフェッショナルサービス(受託開発)

ウインドリバーのプロフェッショナルサービス部門は、CMMIレベル3の評価を受けています。BSP開発サービス、セキュアブートサービス、ソリューションの評価サービスから、コンサルティング、設計サービス、認証サービスまで、組込みソフトウェア業界をリードしてきた経験から培われた知識や専門性、リソースを提供し、お客様の製品の市場投入を支援します。

詳細は以下をご参照ください。www.windriver.com/japan/services

トレーニングサービス

Wind River Linuxの開発に必要な技術に関するオンサイトまたはリモートのプライベートクラスやオンデマンドラーニングを提供しています。

詳細は以下をご参照ください。www.windriver.com/education

主な特長

業界をリードする組込みLinux

  • お客様のアプリケーション向けに最適化できる、高いカスタマイズ性を備えた組込みLinuxソリューション
  • 5年間の標準サポートとメンテナンス。5年後以降も安心できる最長15年のサポートもオプションとして提供
  • 製品に影響を与えるすべての脆弱性と共通脆弱性識別子(CVE)を継続的に監視し、修正パッチを提供
  • 様々なアーキテクチャに対応したボードサポートパッケージ(BSP)を提供し、包括的にハードウェアをサポート
  • インテリジェントエッジシステムの開発、導入、運用、保守を実現するクラウドネイティブのツールをオプションとして提供
  • シングルコア、マルチコアプロセッサ、対称型マルチプロセシング(SMP)をサポート
  • 30種類以上※のリファレンスボードをサポート(※半導体ベンダーのSDKを含む)
  • Yocto Project 3.3および5.10 LTS LinuxカーネルをベースとしたLinuxソリューション
  • 選択できる入手形式は、Yocto Projectベースのソースとして、またはビルド済みのバイナリイメージとしての入手
  • Linux Assembly ToolとOSTreeによるカスタムLinuxイメージの構築、柔軟なアップデートを実現
  • Dockerコンテナを完全にサポート
  • 厳しい認証基準である米国のFACE™ (Future Airborne Capability Environment)に準拠
  • 組込み用途に特化したユーザースペースパッケージの収集・管理が可能
  • ソフトウェア部品表(Software Bill of Materials:SBOM)によるFOSS準拠のアーティファクト。Open Chain 2.1準拠
  • 国際規格の品質マネジメントシステム「ISO 9001:2015」の認証を取得
  • お客様のボードサポートパッケージ(BSP)の開発、製品リリース後のフローズンツリーサポート、マネージドサービスなど、幅広いプロフェッショナルサービスを提供

選択できるLinuxの提供形態

  • LTS(長期サポート):定期的なメンテナンスとCVE修正による長期サポートをベースとした提供形態
  • CD(継続的デリバリー):Yocto ProjectのLTS 21に含まれる最新技術を利用できる継続的デリバリーをベースとした提供形態
  • バイナリディストリビューション:Time-to-valueを短縮可能なLinux Assembly ToolとOSTreeによるバイナリディストリビューション配布による提供形態

プロジェクト単位のプライシング

  • 製品出荷数単位でのロイヤリティは不要
  • プロジェクト単位での価格設定
  • 製品リリースの追加やボードサポートパッケージ(BSP)開発(オプション)

セキュリティ

  • セキュアブート(デジタル署名付きイメージ)に対応
  • ウインドリバーによる共通脆弱性識別子(CVE)の継続的なモニタリングと解消
  • Linuxの標準的なセキュリティ機能であるSElinuxおよびPAMに対応

DevOps開発プロセスにも対応

  • 毎日3,000種類のビルドを検証
  • 60,000超のテストケースを実施
  • 全スプリントリリースは、GAテスト実施済み
  • 共通脆弱性識別子(CVE)の継続的なモニタリングと解消

コンパニオン製品

Wind River Studio

  • ミッションクリティカルなインテリジェントエッジシステムの開発、デプロイ、運用、サービスをおこなうためのクラウドネイティブプラットフォーム
  • ライフサイクル全体を通してスケーラブルにサポートできるように設計されており、ビジネスの成功までの時間を短縮
  • インテリジェントエッジシステムに不可欠なDevSecOpsに対応可能なビルド環境
  • 継続的な統合とデプロイ(CI/CD)環境による複数の並列ワークフローの実現
  • ベストプラクティスを共有できるWebインタフェース

Smart Linux Solutions for the Intelligent Edge

play
CHOOSE-YOUR-OWN WEBINAR

   Smart Linux Solutions   
  for the Intelligent Edge
  

Linux is the default environment for most software developers, but enterprise Linux distributions are often not suitable for the embedded systems used in edge computing.

Join Jay Kruemcke, product line manager at Wind River®, as he discusses how purpose-built embedded Linux distributions can provide the smaller footprint, longer support lifecycle, and high reliability necessary for the intelligent edge.

Jay Kruemcke

   Choose Your Chapters   

 
play Introducing WR Linux

Introducing Wind River Linux

play The Wind River Difference

The Wind River Difference

play Embedded Linux Distro

Embedded Linux Distro

play Build Vs. Buy

Build vs. Buy

play Embedded Linux Market Need & Requirements

Embedded Linux Market Need & Requirements

play Executive Summary with Q&A

Executive Summary & Five Key Questions Answered

 
 

Wind River Studio Linux Services

Wind River 
Linux Services 

Wind River is your embedded Linux lifecycle partner. With more than 16 years of successfully deploying embedded Linux platforms, we know what it takes when it matters most.

 

We interviewed hundreds of Linux customers to identify the solutions they’re looking for to address their biggest challenges. Explore our findings below and see how Wind River® Linux Services can help.

Choose up to 2 solutions to explore.

See which service customers prefer.

Global Footprint »

 
 

150 experts in 10 design centers available 24/7/365 for local and global design, delivery, IP, processes, and support.

» Learn more

Industry Leader »

 
 

Awarded total quality management honors across the globe and the prestigious Service Capability & Performance Standards certification.

» See awards

Multiple Industries »

 
 

Market leader in telecommunications, aerospace, defense, medical, automotive, energy, and industrial applications.

Ecosystems »

 
 

Highly integrated with NXP, AMD, Nvidia, Intel, TI, Broadcom, Marvel, and commercial off-the-shelf board vendors, with thousands of BSPs supported.

» Find BSPs

Mission-Critical  
  Expertise »

 
 

More than 600 safety or mission-critical designs in deployment today with extreme complexity in rigid deployment environments​.

» See space projects
» Explore Services

Wind River Linux Services delivers embedded Linux platform solution design, implementation, security, and lifecycle management capabilities that help you reduce your open source project risk while accelerating time to application deployment, so you can lower your total cost of ownership and focus your valuable resources on innovation.​

Alleviating Technical Debt

The exponential increase in security vulnerabilities is one of the leading causes of unexpected technical debt. As development teams push to add new features and get to market faster, CVEs often go unaddressed until late in the development lifecycle, impacting quality and overall project success.

Try our calculator to see how planning for security across the lifecycle can help alleviate technical debt.

Try the Calculator

Resources

オートモーティブ


 

業界リーダーからのメッセージ

Podcast

フォード社 Matt Jones氏

Podcast

キャデラック社 Melissa Grady氏

自動車関連企業がウインドリバーを採用

As Featured in Forbes

自動車業界のリーダーの5人に1人が、これからはインテリジェントシステムが主要なビジネスモデルになると見ています。

自動車のアイデアは1800年代後半にドイツとフランスで生まれましたが、真の自動車産業革命は1920年代にアメリカで起こりました。

>>  Forbesの記事を読む
One In Five Automotive Industry Leaders

インテリジェントシステムの未来の特性:成功の指標となる12の特性

米国では2030年までに、7兆ドル規模の経済をマシンエコノミーが牽引すると予想されています。企業はその過程で、データドリブンなソフトウェア企業になっていくでしょう。こうした動きに事業の命運を賭けている企業のリーダー達は、成功までの道筋や到達点について、すでに考え始めています。

>>  Forbesの記事を読む
Characteristics Of An Intelligent Systems Future

「車両、都市、デバイス、道路をつなぐコネクテッドネットワークが、完全な自動運転に対応する」 1
frost & sullivan

自動運転車の
最先端

フロスト&サリバン社の予測では、これからは完全自動運転のテクノロジーが成熟し、まずはトラックやオフハイウェイ車両に導入され、乗用車がそれに続くとされています。現在すでに、米国、欧州、アジアを始めとする各国の主要路で、ロボティクストラックの試験走行が数多く行われています。一方でフロスト&サリバン社は、「車両、都市、デバイス、道路をつなぐコネクテッドネットワークが完全な自動運転に対応する」のは、2035年になるだろうと予測しています。1

>>  記事を読む

1 Deenadayalan, Mugundhan, “Autonomous Driving Will Convert Drivers to Pilots,” Frost & Sullivan, September 13, 2019