An Embedded Key Management System for PUF-based Security Enclosures

被引:0
作者
Obermaier, Johannes [1 ]
Hauschild, Florian [1 ]
Hiller, Matthias [1 ]
Sigl, Georg [1 ,2 ]
机构
[1] Fraunhofer Inst AISEC, Garching, Germany
[2] Tech Univ Munich, Chair Secur Informat Technol, Munich, Germany
来源
2018 7TH MEDITERRANEAN CONFERENCE ON EMBEDDED COMPUTING (MECO) | 2018年
关键词
Key Management; RTOS; PUF; Security Enclosure; Embedded System; Firmware Architecture; HSM; FIPS; 140-2;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Hardware Security Modules (HSMs) are embedded systems which provide a physically secured environment for data storage and handling. The device is protected by an enclosure against adversaries. A supervisor circuit monitors the enclosure's integrity and deletes all Critical Security Parameters (CSPs), such as keys, upon a tamper event. While current solutions store CSPs in battery-backed memory, our novel batteryless solution exploits the Physical Unclonable Function (PUF) of the enclosure to derive a key encryption key (KEK). However, such a PUF-based solution requires a more complex Embedded Key Management System (EKMS) for integrity verification, PUF usage, and key management. In this paper, we address this issue by discussing an adversary model, deriving design requirements, and presenting a hardened firmware architecture for PUF-based security enclosures. We present the complementing security extensions for FreeRTOS that enhance the operating system's security. To verify the concept's feasibility, we implement the proposed system and evaluate its performance. Our results show that this security architecture for an EKMS can serve as a firmware basis for novel PUF-based HSMs.
引用
收藏
页码:161 / 166
页数:6
相关论文
共 11 条
[1]  
[Anonymous], 2001, FIPS PUB
[2]  
[Anonymous], 2010, CORT M4 TECHN REF MA
[3]  
Hennig M., 2013, DACH SECURITY
[4]  
Immler V., 2018, IEEE INT S HARDW OR
[5]  
Isaacs P., 2013, PAN PAC S
[6]   A Measurement System for Capacitive PUF-Based Security Enclosures [J].
Obermaier, Johannes ;
Immler, Vincent ;
Hiller, Matthias ;
Sigl, Georg .
2018 55TH ACM/ESDA/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2018,
[7]  
SOGIS, 2013, APPL ATT POT SMARTC
[8]  
Suh G. E., 2005, ACM SIGARCH COMPUTER, V33
[9]  
Suh G. E., 2014, ACM INT C SUP 25 ANN
[10]  
Vai M., 2016, MIT LINCOLN LAB J, V22