...
首页> 外文期刊>ACM Transactions on Embedded Computing Systems >Configurable Memory Security in Embedded Systems
【24h】

Configurable Memory Security in Embedded Systems

机译:嵌入式系统中的可配置内存安全性

获取原文
获取原文并翻译 | 示例
           

摘要

System security is an increasingly important design criterion for many embedded systems. These systems are often portable and more easily attacked than traditional desktop and server computing systems. Key requirements for system security include defenses against physical attacks and lightweight support in terms of area and power consumption. Our new approach to embedded system security focuses on the protection of application loading and secure application execution. During secure application loading, an encrypted application is transferred from on-board flash memory to external double data rate synchronous dynamic random access memory (DDR-SDRAM) via a microprocessor. Following application loading, the core-based security technique provides both confidentiality and authentication for data stored in a microprocessor's system memory. The benefits of our low overhead memory protection approaches are demonstrated using four applications implemented in a field-programmable gate array (FPGA) in an embedded system prototyping platform. Each application requires a collection of tasks with varying memory security requirements. The configurable security core implemented on-chip inside the FPGA with the microprocessor allows for different memory security policies for different application tasks. An average memory saving of 63% is achieved for the four applications versus a uniform security approach. The lightweight circuitry included to support application loading from flash memory adds about 10% FPGA area overhead to the processor-based system and main memory security hardware.
机译:对于许多嵌入式系统,系统安全性已成为越来越重要的设计标准。这些系统通常是便携式的,比传统的台式机和服务器计算系统更容易受到攻击。系统安全的关键要求包括针对物理攻击的防御以及在面积和功耗方面的轻量级支持。我们针对嵌入式系统安全性的新方法侧重于保护应用程序加载和安全的应用程序执行。在安全应用程序加载期间,加密的应用程序通过微处理器从板载闪存传输到外部双倍数据速率同步动态随机存取存储器(DDR-SDRAM)。在加载应用程序之后,基于内核的安全技术为存储在微处理器系统内存中的数据提供了机密性和身份验证。通过在嵌入式系统原型平台中的现场可编程门阵列(FPGA)中实现的四个应用程序,展示了我们低开销内存保护方法的优势。每个应用程序需要具有不同内存安全性要求的任务的集合。与微处理器一起在FPGA内部片上实现的可配置安全性内核允许针对不同的应用任务使用不同的存储器安全策略。与统一的安全性方法相比,这四个应用程序平均可节省63%的内存。用于支持从闪存加载应用程序的轻量级电路为基于处理器的系统和主存储器安全硬件增加了约10%的FPGA区域开销。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号