• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Hardware Trust Anchor Authentication for Updatable IoT Devices
 
  • Details
  • Full
Options
2024
Conference Paper
Title

Hardware Trust Anchor Authentication for Updatable IoT Devices

Abstract
Secure firmware update mechanisms and Hardware Trust Anchors (HTAs) are crucial in securing future IoT networks. Among others, HTAs can be used to shield security-sensitive data like cryptographic keys from unauthorized access, using hardware isolation. Authentication mechanisms for key usage, however, are difficult to implement since corresponding credentials need to be stored outside the HTA. This makes them vulnerable against host hijacking attacks, which in the end also undermines the security gains of the HTA deployment.
This paper introduces an update-resilient and secure HTA authentication mechanism that secures the HTA authentication credentials on the host. Our concept is based on an integration of the Device Identifier Composition Engine (DICE), a Trusted Computing standard for resource-constrained off-the-shelf devices, with signed update manifest documents. This secures HTA authentication credentials, but also provides value for DICE-based devices without an HTA. We evaluate the feasibility of our solution based on a proof-of-concept implementation.
Author(s)
Lorych, Dominik  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Plappert, Christian  orcid-logo
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Mainwork
ARES 2024, 19th International Conference on Availability, Reliability & Security. Proceedings  
Conference
International Conference on Availability, Reliability and Security 2024  
DOI
10.1145/3664476.3664479
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024