• DocumentCode
    2401872
  • Title

    HSDL: A Security Development Lifecycle for hardware technologies

  • Author

    Khattri, Hareesh ; Mangipudi, Narasimha Kumar V ; Mandujano, Salvador

  • Author_Institution
    Security Center of Excellence (SeCoE), Intel Corp., Hillsboro, OR, USA
  • fYear
    2012
  • fDate
    3-4 June 2012
  • Firstpage
    116
  • Lastpage
    121
  • Abstract
    Security assurance is a rapidly evolving but well understood discipline in the software industry. Many firms have adopted the Security Development Lifecycle as a process to identify and fix vulnerabilities in their products before they are released. To do this, they rely on sound software security practices, tools and precise technical information available through a vast collection of publicly known vulnerabilities and exploits. Historically, secure development practices for hardware products have not developed as fast. Only a limited number of methodologies, standards, exploits, and testing tools exist to assist vendors with their security assurance goals. This paper presents a Hardware Security Development Lifecycle at the hardware technology level that has been used on commercial CPUs, chipsets, and SoCs. It describes how a structured flow of analysis and testing activities organized in five phases can accelerate the discovery of security issues in computer hardware products that could be exploited through software or physical attacks. We summarize lessons learned over several years of security evaluation experience that have resulted in a systematic method that can be adapted to make security assurance an integral part of hardware development cycles.
  • Keywords
    microprocessor chips; security of data; HSDL; fix vulnerabilities; hardware products; hardware security development lifecycle; hardware technologies; security assurance; security development lifecycle; software industry; sound software security; technical information; Hardware; Microprogramming; Registers; Security; Software; System-on-a-chip; Testing; Hardware Security; Hardware Vulnerabilities; Security Development Lifecycle; Security Validation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Hardware-Oriented Security and Trust (HOST), 2012 IEEE International Symposium on
  • Conference_Location
    San Francisco, CA
  • Print_ISBN
    978-1-4673-2341-3
  • Type

    conf

  • DOI
    10.1109/HST.2012.6224330
  • Filename
    6224330