Sancus 2.0: A Low-Cost Security Architecture for IoT Devices

被引:65
|
作者
Noorman, Job [1 ]
Van Bulck, Jo [1 ]
Muhlberg, Jan Tobias [1 ]
Piessens, Frank [1 ]
Maene, Pieter [2 ]
Preneel, Bart [2 ]
Verbauwhede, Ingrid [2 ]
Goetzfried, Johannes [3 ]
Mueller, Tilo [3 ]
Freiling, Felix [3 ]
机构
[1] Katholieke Univ Leuven, iMinds DistriNet, Dept Comp Sci, Celestijnenlaan 200A, B-3001 Leuven, Belgium
[2] Katholieke Univ Leuven, iMinds COSIC, Dept Elect Engn, Kasteelpk Arenberg 10, B-3001 Leuven, Belgium
[3] FAU Erlangen Nurnberg, Dept Comp Sci, Martensstr 3, D-91058 Erlangen, Germany
基金
比利时弗兰德研究基金会;
关键词
Protected Module Architectures; Embedded systems security; Trusted computing; Software security engineering; WIRELESS SENSOR NETWORKS; INTERNET; ATTACKS;
D O I
10.1145/3079763
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-party) software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a software provider that a specific software module is running uncompromised and can provide a secure communication channel between software modules and software providers. Software modules can securely maintain local state and can securely interact with other software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated-both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work.
引用
收藏
页数:33
相关论文
共 50 条
  • [1] Proposal of Low-Cost Automated Security Diagnosis System for IoT Devices
    Ogawa, Kohichi
    Hamamoto, Nobukuni
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON CONSUMER ELECTRONICS, ICCE, 2023,
  • [2] An Innovative Security Architecture for Low Cost Low Power IoT Devices Based on Secure Elements A four quarters security architecture
    Urien, Pascal
    [J]. 2018 15TH IEEE ANNUAL CONSUMER COMMUNICATIONS & NETWORKING CONFERENCE (CCNC), 2018,
  • [3] FastSLAM 2.0 Running On a Low-Cost Embedded Architecture
    Abouzahir, Mohamed
    Elouardi, Abdelhafid
    Bouaziz, Samir
    Latif, Rachid
    Tajer, Abdelouahed
    [J]. 2014 13TH INTERNATIONAL CONFERENCE ON CONTROL AUTOMATION ROBOTICS & VISION (ICARCV), 2014, : 1421 - 1426
  • [4] Low-Cost Memory Fault Tolerance for IoT Devices
    Gottscho, Mark
    Alam, Irina
    Schoeny, Clayton
    Dolecek, Lara
    Gupta, Puneet
    [J]. ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2017, 16
  • [5] VEHIOT: Design and Evaluation of an IoT Architecture Based on Low-Cost Devices to Be Embedded in Production Vehicles
    Pajares Redondo, Jonatan
    Prieto Gonzalez, Lisardo
    Garcia Guzman, Javier
    Boada, Beatriz L.
    Diaz, Vicente
    [J]. SENSORS, 2018, 18 (02)
  • [6] Low-cost Security for Next-generation IoT Networks
    Anagnostopoulos, Nikolaos Athanasios
    Ahmad, Saad
    Arul, Tolga
    Steinmetzer, Daniel
    Hollick, Matthias
    Katzenbeisser, Stefan
    [J]. ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2020, 20 (03)
  • [7] A Low-cost Hardware Attack Detection Solution for IoT Devices
    Lorandel, Jordane
    Khelif, Mohamed Amine
    Romain, Olivier
    [J]. 2022 IEEE 31ST INTERNATIONAL SYMPOSIUM ON INDUSTRIAL ELECTRONICS (ISIE), 2022, : 674 - 679
  • [8] LOIS: Low-cost Packet Header Protection for IoT Devices
    Wang, Minmei
    Shi, Shouqian
    Zhang, Xiaoxue
    Han, Song
    Qian, Chen
    [J]. PROCEEDINGS 8TH ACM/IEEE CONFERENCE ON INTERNET OF THINGS DESIGN AND IMPLEMENTATION, IOTDI 2023, 2023, : 354 - 366
  • [9] Highly Reliable and Low-Cost Symbiotic IOT Devices and Systems
    Lin, Bing-Yang
    Hung, Hsin-Wei
    Tseng, Shu-Mei
    Chen, Chi
    Wu, Cheng-Wen
    [J]. 2017 IEEE INTERNATIONAL TEST CONFERENCE (ITC), 2017,
  • [10] XOR-Based Low-Cost Reconfigurable PUFs for IoT Security
    Liu, Weiqiang
    Zhang, Lei
    Zhang, Zhengran
    Gu, Chongyan
    Wang, Chenghua
    O'Neill, Maire
    Lombardi, Fabrizio
    [J]. ACM TRANSACTIONS ON EMBEDDED COMPUTING SYSTEMS, 2019, 18 (03)