首页> 外文会议>SAE World Congress and Exhibition >How Formal Techniques Can Keep Hackers from Driving You into a Ditch
【24h】

How Formal Techniques Can Keep Hackers from Driving You into a Ditch

机译:如何让黑客阻止黑客让你进入沟渠

获取原文

摘要

The number one priority in vehicle security is to harden the root-of-trust; from which everything else - the hardware, firmware, OS, and application layer’s security - is derived. If the root-of-trust can be compromised, then the whole system is vulnerable. In the near future the root-of-trust will effectively be an encryption key - a digital signature for each vehicle - that will be stored in a secure memory element inside all vehicles. In this paper we will show how a mathematical, formal analysis technique can be applied to ensure that this secure storage cannot (A) be read by an unauthorized party or accidentally “leak” to the outputs or (B) be altered, overwritten, or erased by unauthorized entities. We will include a real-world case study from a consumer electronics maker that has successfully used this technology to secure their products from attacks 24/7/365. Note that the techniques and solutions described herein are focused exclusively on digital circuitry specified in a register transfer level (RTL) language, such as Verilog or VHDL - i.e. the most fundamental level of digital design. This paper does not go into any physical design and verification issues or related “side-channel” attacks, nor do we address firmware or higher level software security best practices.
机译:车辆安全的第一优先级是强化信任根;从哪一切 - 派生硬件,固件,操作系统和应用层的安全性。如果可以损害信任根,则整个系统都很脆弱。在不久的将来,信任根将有效地是加密密钥 - 每个车辆的数字签名 - 这将存储在所有车辆内的安全存储元件中。在本文中,我们将展示如何应用数学,正式分析技术,以确保不授权的一方读取(a)或者意外地将“泄漏”或(b)更改,覆盖或被未经授权的实体删除。我们将包括一项来自消费电子制造商的真实案例研究,该机构已成功使用此技术可从24/7/365攻击中保护其产品。注意,这里描述的技术和解决方案专注于寄存器传输级别(RTL)语言中指定的数字电路,例如VERILOG或VHDL - 即数字设计。本文不会进入任何物理设计和验证问题或相关的“侧通道”攻击,也不会解决固件或更高级别的软件安全性最佳实践。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号