A Novel Holistic Security Framework for In-Field Firmware Updates

K. SudeendraKumar, S. Sahoo, K. Kiran, Ayass Kant Swain, K. Mahapatra
{"title":"A Novel Holistic Security Framework for In-Field Firmware Updates","authors":"K. SudeendraKumar, S. Sahoo, K. Kiran, Ayass Kant Swain, K. Mahapatra","doi":"10.1109/ises.2018.00063","DOIUrl":null,"url":null,"abstract":"The software/firmware running on the electronic devices is regularly updated. In IoT devices, the updates are performed Over the Air (OTA) through internet. In the absence of proper security measures, OTA update feature can be misused. The security threats like firmware reverse engineering, loading unauthorized firmware and loading authorized firmware on unauthorized nodes will lead to misuse of intellectual property, product cloning and denial of service attack. In this paper, we propose a security framework the microcontroller/SoC devices can incorporate for secure in-field OTA firmware update process. The proposed holistic solution support JTAG security, protecting IP rights of original device manufacturer (ODM) and secure OTA update. The security framework is designed using suitable cryptographic algorithms and protocol measures to address all the security threats connected with OTA firmware/software update which is not addressed in the past techniques.","PeriodicalId":447663,"journal":{"name":"2018 IEEE International Symposium on Smart Electronic Systems (iSES) (Formerly iNiS)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2018-12-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE International Symposium on Smart Electronic Systems (iSES) (Formerly iNiS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ises.2018.00063","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

The software/firmware running on the electronic devices is regularly updated. In IoT devices, the updates are performed Over the Air (OTA) through internet. In the absence of proper security measures, OTA update feature can be misused. The security threats like firmware reverse engineering, loading unauthorized firmware and loading authorized firmware on unauthorized nodes will lead to misuse of intellectual property, product cloning and denial of service attack. In this paper, we propose a security framework the microcontroller/SoC devices can incorporate for secure in-field OTA firmware update process. The proposed holistic solution support JTAG security, protecting IP rights of original device manufacturer (ODM) and secure OTA update. The security framework is designed using suitable cryptographic algorithms and protocol measures to address all the security threats connected with OTA firmware/software update which is not addressed in the past techniques.
一种新的现场固件更新整体安全框架
在电子设备上运行的软件/固件会定期更新。在物联网设备中,更新是通过互联网通过空中(OTA)执行的。在没有适当的安全措施的情况下,OTA更新功能可能会被滥用。固件逆向工程、加载未经授权的固件以及在未经授权的节点上加载授权的固件等安全威胁会导致知识产权滥用、产品克隆和拒绝服务攻击。在本文中,我们提出了一个安全框架,微控制器/SoC器件可以纳入安全的现场OTA固件更新过程。整体解决方案支持JTAG安全,保护ODM的IP权益和OTA安全升级。安全框架使用合适的加密算法和协议措施来设计,以解决与OTA固件/软件更新相关的所有安全威胁,这些威胁在过去的技术中没有解决。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信