Secure Resource Sharing for Embedded Protected Module Architectures
Jo Van Bulck, Job Noorman, Jan T
- bias Mühlberg and
Secure Resource Sharing for Embedded Protected Module Architectures - - PowerPoint PPT Presentation
Secure Resource Sharing for Embedded Protected Module Architectures Jo Van Bulck, Job Noorman, Jan T obias Mhlberg and Frank Piessens August 24, 2015 Contents 1. Embedded Problem Domain 2. Protected Module Architectures 3.
2
3
VIEGA John, THOMPSON Hugh, The state of embedded-device security (spoiler alert: It's bad), IEEE Security & Privacy (10.5), September 2012, pp. 68-70.
4
5
6
STRACKX Raoul et al., Protected Software Module Architectures, ISSE 2013 Securing Electronic Business Processes, Springer Fachmedien Wiesbaden, 2013, pp. 241-251.
F r
t
r
e c t e d U n p r
e c t e d E n t r y C
e D a t a P r
e c t e d r
r
r w
w x U n p r
e c t e d/
h e r S P M r
r
w x
7
STRACKX Raoul et al., Protected Software Module Architectures, ISSE 2013 Securing Electronic Business Processes, Springer Fachmedien Wiesbaden, 2013, pp. 241-251.
F r
t
r
e c t e d U n p r
e c t e d E n t r y C
e D a t a P r
e c t e d r
r
r w
w x U n p r
e c t e d/
h e r S P M r
r
w x
PC
8
NOORMAN Job et al., Sancus: Low-cost Trustworthy Extensible Networked Devices with a Zero-software Trusted Computing Base, Proceedings of the 22nd USENIX conference on Security symposium, 2013, pp. 479-494.
9
10
11
Embedded device
12
Embedded device
13
14
15
P r
e c t e d fi l e s y s t e m S Ms
f s
b
n d a r y
MMI O
C F S A P I
C F S A P I
A
B
S F S A P I
S y s t e m b
n d a r y
16
P r
e c t e d fi l e s y s t e m S Ms
f s
b
n d a r y
MMI O
C F S A P I
C F S A P I
A
B
S F S A P I
S y s t e m b
n d a r y
UNIX like fjle system API (incl. chmod)
17
P r
e c t e d fi l e s y s t e m S Ms
f s
b
n d a r y
MMI O
C F S A P I
C F S A P I
A
B
S F S A P I
S y s t e m b
n d a r y
Access control using sancus_get_caller_id UNIX like fjle system API (incl. chmod)
18
P r
e c t e d fi l e s y s t e m S Ms
f s
b
n d a r y
MMI O
C F S A P I
C F S A P I
A
B
S F S A P I
S y s t e m b
n d a r y
Access control using sancus_get_caller_id Pluggable private back-end encapsulating resource UNIX like fjle system API (incl. chmod)
19
20
21
22