To improve the user experience on this site we use cookies. I agree | I disagree

Secure S1 Cellular Routers

Secure boot, integrity checks, compliance with the most up to date cryptographic and security recommendations… S1 Routers represent an entirely new standard in security and cybersecurity threat resistance for Advantech Cellular Routers.  

In combination with hardware capabilities (CPU, OTP memory) and hardened Linux/ICR-OS, S1 Routers provide the simplicity of a web-based configuration with limited flexibility known from our standard product open platforms in exchange for a higher security level applied to S1 devices.  

S1 Routers fitting to applications where compliance with IEC 62443-4-2 SL1 (level 1), BSI IT Security label rules and others is required. For currently available formal certification, take a look at the datasheets for relevant router models or contact Advantech support.

S1 Router Differentiation

Key Differences Between S1 Routers and Standard RoutersS1 RoutersStandard products
Compliance with IEC 62443-4-2 SL1 (level 1), BSI IT Security label rules and requirements*YesNo
Secure bootYesNo
Read-only filesystem with integrity checksYesNo
Default usernameadminroot
Router App format.raw.tgz
Min password requirements**12 chars, 3 classes6 chars, 1 class
Mandatory account lockYesNo
Available cryptographic algorithms**strong onlyboth weak and strong
Web AdminHTTPS onlyHTTP and/or HTTPS
OpenVPN Security Level2 (medium) .. 5 (very high)0 (weak) .. 5 (very high)
FTP and TelnetNoYes
FW Support End indicatorYesNo
Advanced Intrusion Detection Environment (AIDE)YesNo
Encrypted firmware imageYesNo
Using scripts***NoYes
Root access (sudo)limited set of commandsfull
Wi-Fi AP/Station "Extra Options"NoYes
HTTP Content-Security-Policystrictpermissive
Persistent syslogmandatoryoptional
IPsec aggressive modeNoYes
Persistent data storagecombined (/var)router apps (/opt), user data (/var/data)

* Compliance does not mean formal approval; for scope of available formal approvals, contact the producer.

** Weak algorithms: strength < 128 bits (e.g. DES, 3DES, MD5, SHA-1, RSA-1024/2048)

Strong algorithms: strength ≥ 128 bits (e.g. SHA-256+, RSA-3072+, ED25519)

More info: Strength criteria explained in Security Guidelines, Section 1.2

*** The only way to use scripts is to convert required scripts into S1 Router Apps.

 

Above mentioned differences outline the general use and convenience for different customer applications. Standard products provide large flexibility to configure the router for almost any application case. The S1 Routers limits need to be reviewed more carefully with application requirements to decide whether convenient or not.

S1 Router GUI

What remains the same is the familiar look of the S1 Router's web interface for configuration.

Customers can operate a familiar interface, logically segmented into categories.

S1 Router availability and production

S1 Routers are only available for selected router models. You can easily identify them by the “-S1” suffix at the end of the part number (e.g., ICR-2734-S1). It is possible to expand the list to include other part numbers, depending on project volume and technical feasibility (not all routers in our production range can be modified to become S1 Routers). This requires prior agreement, after which a new part number must be created for ordering.

Throughout their lifecycle, S1 Routers benefit from regular updates provided specifically for this product group, using a dedicated firmware branch called ICR-OS S1, available on our website. As noted above, uploading this firmware to standard units is not possible. The ICR-OS S1 firmware branch is developed exclusively to work with S1 Routers.

S1 Router compatibility

 

S1 Routers do not support native scripting due to security reasons, unlike standard products. However, it is possible to extend the standard firmware functionalities using well-known Router Apps. These Router Apps differ from those used with the standard ICR-OS firmware, so it is necessary to use dedicated S1 Router Apps, which have the “.raw” extension.

Customers can also develop their own S1 Router Apps in the .raw format. In such cases, the developer is fully responsible for the security of the software they create.

Check the list of available Router Apps

 

It is also possible to use S1 Routers in combination with other routers and various monitoring or management systems, provided the communication scenario in the application allows it (see the S1 Routers Differentiation chapter mentioned earlier).

FAQ

?Is there any difference in GUI between standard routers and S1 Routers?
The GUI remains the same, making it very familiar to any user of our current routers. For standard users who use the GUI for configuration, there is virtually no difference between a standard router and an S1 Router. You can identify that you are configuring an S1 Router by the “S1” label in the router model name within the web GUI, as well as by the orange color scheme, which distinguishes it from the green color used in the standard production web GUI.
?Is it possible to make an S1 Router from any cellular router in the Advantech portfolio?
No, this is not possible. S1 Routers require an OTP (One-Time Programmable) memory section, which is not available on all Advantech routers. If you need a product that is not currently available as an S1 Router, please contact the manufacturer to discuss your requirements.
?I already have Advantech routers in my network. Is it possible to update them to S1 Routers?
No, this is not possible. Routers must be ordered as S1 Routers and produced as such directly at Advantech's manufacturing facility.
?I am currently operating scripts on standard Advantech routers – can I use those scripts with S1 Routers?
Scripts are not supported on S1 Routers due to security reasons. If you need to customize router behavior, you can create a Router App for S1 Routers in the .raw format and upload it to the router(s).
?Can I use Router Apps designed for standard Advantech routers on S1 Routers?
No, this is not possible. Only Router Apps developed specifically for S1 Routers, with the .raw extension, can be used. See the list here.
?Is IEC 62443-4-2 SL1 (Level 1) or BSI IT Security Label certification available for S1 Routers?
S1 Routers are produced in line with the recommendations of the above-mentioned certifications. However, formal certification is not available for all models. For information on currently available or planned certifications for specific part numbers, please consult the datasheet or contact Advantech specialists for the required details.
?Is the firmware for S1 Routers regularly updated?
Yes, the firmware is continuously developed to address the latest security recommendations and to improve the overall customer experience. Firmware updates are performed in the same way as with standard products, using the dedicated ICR-OS S1 firmware branch.