DocumentCode :
2137385
Title :
Internet Firewalls in the DECOS System-on-a-Chip Architecture
Author :
Wasicek, Armin ; Elmenreich, Wilfried
Author_Institution :
Vienna Univ. of Technol., Vienna
Volume :
2
fYear :
2007
fDate :
23-27 June 2007
Firstpage :
983
Lastpage :
988
Abstract :
A big part of requests in today´s Internet are malicious connection attempts aimed at compromising hosts in order to gain illegal access. Intrusion tools perform automatic scans to seek out promising targets, probe for vulnerabilities, and even mount autonomous attacks. Outgoing from this scenario, this paper discusses approaches to govern access to a network of System-on-a-Chip (SoC) components that provides an Ethernet interface to the Internet for maintenance purposes. Security measures are needed to protect the SoC from unauthorized access to internal information such as diagnostic interfaces or bus communication. Since the SoC should be realized as a compact embedded system, the implementation of security mechanisms has to fit the available processing and memory resources. In order to be able to cope with changing security requirements and different deployment environments a multi-level security architecture is proposed. The architecture partitions the system into intrusion containment regions and provides corresponding access privileges. As part of the architecture, the implementation of an Internet Firewall providing low level authentication to a network of SoC s is shown.
Keywords :
Internet; authorisation; embedded systems; local area networks; message authentication; system buses; system-on-chip; DECOS system-on-a-chip architecture; Ethernet interface; Internet firewall; bus communication; embedded system; illegal access; intrusion detection; malicious connection; multi level security architecture; unauthorized access; Authentication; Communication system security; Embedded system; Ethernet networks; IP networks; Information security; Internet; Probes; Protection; System-on-a-chip; DECOS SOC architecture; Embedded systems security; Time-Triggered Ethernet; firewall;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Industrial Informatics, 2007 5th IEEE International Conference on
Conference_Location :
Vienna
ISSN :
1935-4576
Print_ISBN :
978-1-4244-0851-1
Electronic_ISBN :
1935-4576
Type :
conf
DOI :
10.1109/INDIN.2007.4384908
Filename :
4384908
Link To Document :
بازگشت