An Embedded Key Management System for PUF-based Security Enclosures

被引:0
|
作者
Obermaier, Johannes [1 ]
Hauschild, Florian [1 ]
Hiller, Matthias [1 ]
Sigl, Georg [1 ,2 ]
机构
[1] Fraunhofer Inst AISEC, Garching, Germany
[2] Tech Univ Munich, Chair Secur Informat Technol, Munich, Germany
来源
2018 7TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO) | 2018年
关键词
Key Management; RTOS; PUF; Security Enclosure; Embedded System; Firmware Architecture; HSM; FIPS; 140-2;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Hardware Security Modules (HSMs) are embedded systems which provide a physically secured environment for data storage and handling. The device is protected by an enclosure against adversaries. A supervisor circuit monitors the enclosure's integrity and deletes all Critical Security Parameters (CSPs), such as keys, upon a tamper event. While current solutions store CSPs in battery-backed memory, our novel batteryless solution exploits the Physical Unclonable Function (PUF) of the enclosure to derive a key encryption key (KEK). However, such a PUF-based solution requires a more complex Embedded Key Management System (EKMS) for integrity verification, PUF usage, and key management. In this paper, we address this issue by discussing an adversary model, deriving design requirements, and presenting a hardened firmware architecture for PUF-based security enclosures. We present the complementing security extensions for FreeRTOS that enhance the operating system's security. To verify the concept's feasibility, we implement the proposed system and evaluate its performance. Our results show that this security architecture for an EKMS can serve as a firmware basis for novel PUF-based HSMs.
引用
收藏
页码:161 / 166
页数:6
相关论文
共 50 条
  • [1] A Measurement System for Capacitive PUF-Based Security Enclosures
    Obermaier, Johannes
    Immler, Vincent
    Hiller, Matthias
    Sigl, Georg
    2018 55TH ACM/ESDA/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2018,
  • [2] Cyber Security Protocol for Secure Traffic Monitoring Systems using PUF-based Key Management
    Pudi, Vikramkumar
    Bodapati, Srinivasu
    Kumar, Sachin
    Chattopadhyay, Anupam
    2020 6TH IEEE INTERNATIONAL SYMPOSIUM ON SMART ELECTRONIC SYSTEMS (ISES 2020) (FORMERLY INIS), 2020, : 103 - 108
  • [3] A PUF-Based Paradigm for IoT Security
    Idriss, Tarek
    Idriss, Haytham
    Bayoumi, Magdy
    2016 IEEE 3RD WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2016, : 700 - 705
  • [4] A Novel PUF-Based Encryption Protocol for Embedded System On Chip
    Stanciu, Alexandra
    Moldoveanu, Florin Dumitru
    Cirstea, Marcian
    2016 13TH INTERNATIONAL CONFERENCE ON DEVELOPMENT AND APPLICATION SYSTEMS (DAS 2016), 2016, : 158 - 165
  • [5] The Past, Present, and Future of Physical Security Enclosures: From Battery-Backed Monitoring to PUF-Based Inherent Security and Beyond
    Johannes Obermaier
    Vincent Immler
    Journal of Hardware and Systems Security, 2018, 2 (4) : 289 - 296
  • [6] PUF-based key distribution in wireless sensor networks
    Zhang Z.
    Liu Y.
    Zuo Q.
    Harn L.
    Qiu S.
    Cheng Y.
    Computers, Materials and Continua, 2020, 64 (02): : 1261 - 1280
  • [7] PUF-Based Key Distribution in Wireless Sensor Networks
    Zhang, Zheng
    Liu, Yanan
    Zuo, Qinyuan
    Harn, Lein
    Qiu, Shuo
    Cheng, Yuan
    CMC-COMPUTERS MATERIALS & CONTINUA, 2020, 64 (02): : 1261 - 1280
  • [8] A PUF-based cryptographic security solution for IoT systems on chip
    Alexandra Balan
    Titus Balan
    Marcian Cirstea
    Florin Sandu
    EURASIP Journal on Wireless Communications and Networking, 2020
  • [9] Challenging the security of "A PUF-based hardware mutual authentication protocol"
    Adeli, Morteza
    Bagheri, Nasour
    Martin, Honorio
    Peris-Lopez, Pedro
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2022, 169 : 199 - 210
  • [10] A New Secure Scan Design with PUF-based Key for Authentication
    Wang, Qidong
    Cui, Aijiao
    Qu, Gang
    Li, Huawei
    2020 IEEE 38TH VLSI TEST SYMPOSIUM (VTS 2020), 2020,