An Embedded Key Management System for PUF-based Security Enclosures

被引:0
|
作者
Obermaier, Johannes [1 ]
Hauschild, Florian [1 ]
Hiller, Matthias [1 ]
Sigl, Georg [1 ,2 ]
机构
[1] Fraunhofer Inst AISEC, Garching, Germany
[2] Tech Univ Munich, Chair Secur Informat Technol, Munich, Germany
关键词
Key Management; RTOS; PUF; Security Enclosure; Embedded System; Firmware Architecture; HSM; FIPS; 140-2;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Hardware Security Modules (HSMs) are embedded systems which provide a physically secured environment for data storage and handling. The device is protected by an enclosure against adversaries. A supervisor circuit monitors the enclosure's integrity and deletes all Critical Security Parameters (CSPs), such as keys, upon a tamper event. While current solutions store CSPs in battery-backed memory, our novel batteryless solution exploits the Physical Unclonable Function (PUF) of the enclosure to derive a key encryption key (KEK). However, such a PUF-based solution requires a more complex Embedded Key Management System (EKMS) for integrity verification, PUF usage, and key management. In this paper, we address this issue by discussing an adversary model, deriving design requirements, and presenting a hardened firmware architecture for PUF-based security enclosures. We present the complementing security extensions for FreeRTOS that enhance the operating system's security. To verify the concept's feasibility, we implement the proposed system and evaluate its performance. Our results show that this security architecture for an EKMS can serve as a firmware basis for novel PUF-based HSMs.
引用
收藏
页码:161 / 166
页数:6
相关论文
共 50 条
  • [1] A Measurement System for Capacitive PUF-Based Security Enclosures
    Obermaier, Johannes
    Immler, Vincent
    Hiller, Matthias
    Sigl, Georg
    2018 55TH ACM/ESDA/IEEE DESIGN AUTOMATION CONFERENCE (DAC), 2018,
  • [2] Attacks and Countermeasures for Capacitive PUF-Based Security Enclosures
    Garb, Kathrin
    Schink, Marc
    Hiller, Matthias
    Obermaier, Johannes
    PROCEEDINGS OF THE 2021 IEEE INTERNATIONAL CONFERENCE ON PHYSICAL ASSURANCE AND INSPECTION ON ELECTRONICS (PAINE), 2021,
  • [3] The Wiretap Channel for Capacitive PUF-Based Security Enclosures
    Garb K.
    Xhemrishi M.
    Kürzinger L.
    Frisch C.
    IACR Trans. Cryptogr. Hardw. Embed. Syst., 2022, 3 (165-191): : 165 - 191
  • [4] A novel PUF-Based key management scheme for DTMSN
    Information Security Center, Beijing University of Posts and Telecommunications, Beijing 100876, China
    不详
    不详
    J. Convergence Inf. Technol., 2012, 12 (372-381):
  • [5] Cyber Security Protocol for Secure Traffic Monitoring Systems using PUF-based Key Management
    Pudi, Vikramkumar
    Bodapati, Srinivasu
    Kumar, Sachin
    Chattopadhyay, Anupam
    2020 6TH IEEE INTERNATIONAL SYMPOSIUM ON SMART ELECTRONIC SYSTEMS (ISES 2020) (FORMERLY INIS), 2020, : 103 - 108
  • [6] On the Security of a PUF-Based Authentication and Key Exchange Protocol for IoT Devices
    Sun, Da-Zhi
    Gao, Yi-Na
    Tian, Yangguang
    SENSORS, 2023, 23 (14)
  • [7] A PUF-Based Paradigm for IoT Security
    Idriss, Tarek
    Idriss, Haytham
    Bayoumi, Magdy
    2016 IEEE 3RD WORLD FORUM ON INTERNET OF THINGS (WF-IOT), 2016, : 700 - 705
  • [8] Smart Grid Security: A PUF-Based Authentication and Key Agreement Protocol
    Bagheri, Nasour
    Bendavid, Ygal
    Safkhani, Masoumeh
    Rostampour, Samad
    FUTURE INTERNET, 2024, 16 (01)
  • [9] A Novel PUF-Based Encryption Protocol for Embedded System On Chip
    Stanciu, Alexandra
    Moldoveanu, Florin Dumitru
    Cirstea, Marcian
    2016 13TH INTERNATIONAL CONFERENCE ON DEVELOPMENT AND APPLICATION SYSTEMS (DAS 2016), 2016, : 158 - 165
  • [10] Security Analysis of Index-Based Syndrome Coding for PUF-Based Key Generation
    Becker, Georg T.
    Wild, Alexander
    Gueneysu, Tim
    2015 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2015, : 20 - 25