DocumentCode :
2401872
Title :
HSDL: A Security Development Lifecycle for hardware technologies
Author :
Khattri, Hareesh ; Mangipudi, Narasimha Kumar V ; Mandujano, Salvador
Author_Institution :
Security Center of Excellence (SeCoE), Intel Corp., Hillsboro, OR, USA
fYear :
2012
fDate :
3-4 June 2012
Firstpage :
116
Lastpage :
121
Abstract :
Security assurance is a rapidly evolving but well understood discipline in the software industry. Many firms have adopted the Security Development Lifecycle as a process to identify and fix vulnerabilities in their products before they are released. To do this, they rely on sound software security practices, tools and precise technical information available through a vast collection of publicly known vulnerabilities and exploits. Historically, secure development practices for hardware products have not developed as fast. Only a limited number of methodologies, standards, exploits, and testing tools exist to assist vendors with their security assurance goals. This paper presents a Hardware Security Development Lifecycle at the hardware technology level that has been used on commercial CPUs, chipsets, and SoCs. It describes how a structured flow of analysis and testing activities organized in five phases can accelerate the discovery of security issues in computer hardware products that could be exploited through software or physical attacks. We summarize lessons learned over several years of security evaluation experience that have resulted in a systematic method that can be adapted to make security assurance an integral part of hardware development cycles.
Keywords :
microprocessor chips; security of data; HSDL; fix vulnerabilities; hardware products; hardware security development lifecycle; hardware technologies; security assurance; security development lifecycle; software industry; sound software security; technical information; Hardware; Microprogramming; Registers; Security; Software; System-on-a-chip; Testing; Hardware Security; Hardware Vulnerabilities; Security Development Lifecycle; Security Validation;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Hardware-Oriented Security and Trust (HOST), 2012 IEEE International Symposium on
Conference_Location :
San Francisco, CA
Print_ISBN :
978-1-4673-2341-3
Type :
conf
DOI :
10.1109/HST.2012.6224330
Filename :
6224330
Link To Document :
بازگشت