Securing and Hardening Embedded Linux Devices - case study based on NXP i.MX6 Platform

Marcin Bajer
{"title":"Securing and Hardening Embedded Linux Devices - case study based on NXP i.MX6 Platform","authors":"Marcin Bajer","doi":"10.1109/FiCloud57274.2022.00032","DOIUrl":null,"url":null,"abstract":"We have already gotten used to the fact software has become an integral part of almost every device we use. We are slowly getting used to our devices being interconnected with each other, controlling and monitoring crucial elements of our daily life and exchanging our private data. We are putting more and more trust in the embedded devices that are designed to help us out. Securing embedded devices was always a challenging task, but ubiquitous connectivity made it even much more important and difficult. As devices become smarter and highly interconnected there is more room for cybercriminals to exploit the system’s vulnerabilities to issue malicious control commands or create data breaches. The purpose of this paper is to describe the main security measures for protecting embedded Linux-based systems. It describes details of the implementation of a secure boot and a secure storage mechanism using embedded hardware features of NXP i.MX6 platform. In addition, the paper discusses methods for secure connection to the cloud and device provisioning with the support of TPM module. Overall, it provides practical guidelines on how to develop an embedded Linux device having security considerations in mind and summarizes the current state of knowledge on the topic.","PeriodicalId":349690,"journal":{"name":"2022 9th International Conference on Future Internet of Things and Cloud (FiCloud)","volume":"8 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 9th International Conference on Future Internet of Things and Cloud (FiCloud)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FiCloud57274.2022.00032","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

We have already gotten used to the fact software has become an integral part of almost every device we use. We are slowly getting used to our devices being interconnected with each other, controlling and monitoring crucial elements of our daily life and exchanging our private data. We are putting more and more trust in the embedded devices that are designed to help us out. Securing embedded devices was always a challenging task, but ubiquitous connectivity made it even much more important and difficult. As devices become smarter and highly interconnected there is more room for cybercriminals to exploit the system’s vulnerabilities to issue malicious control commands or create data breaches. The purpose of this paper is to describe the main security measures for protecting embedded Linux-based systems. It describes details of the implementation of a secure boot and a secure storage mechanism using embedded hardware features of NXP i.MX6 platform. In addition, the paper discusses methods for secure connection to the cloud and device provisioning with the support of TPM module. Overall, it provides practical guidelines on how to develop an embedded Linux device having security considerations in mind and summarizes the current state of knowledge on the topic.
嵌入式Linux设备的安全加固——基于NXP i.MX6平台的案例研究
我们已经习惯了这样一个事实:软件已经成为我们使用的几乎所有设备中不可或缺的一部分。我们正在慢慢习惯我们的设备相互连接,控制和监控我们日常生活的关键要素,交换我们的私人数据。我们越来越信任那些旨在帮助我们摆脱困境的嵌入式设备。保护嵌入式设备始终是一项具有挑战性的任务,但无处不在的连接使其变得更加重要和困难。随着设备变得更加智能和高度互联,网络犯罪分子利用系统漏洞发出恶意控制命令或造成数据泄露的空间更大。本文的目的是描述保护基于linux的嵌入式系统的主要安全措施。介绍了利用NXP i.MX6平台的嵌入式硬件特性实现安全引导和安全存储机制的细节。此外,本文还讨论了在TPM模块的支持下安全连接云端和设备配置的方法。总的来说,它提供了关于如何在考虑安全性的情况下开发嵌入式Linux设备的实用指导方针,并总结了有关该主题的当前知识状态。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信