DocumentCode
2401872
Title
HSDL: A Security Development Lifecycle for hardware technologies
Author
Khattri, Hareesh ; Mangipudi, Narasimha Kumar V ; Mandujano, Salvador
Author_Institution
Security Center of Excellence (SeCoE), Intel Corp., Hillsboro, OR, USA
fYear
2012
fDate
3-4 June 2012
Firstpage
116
Lastpage
121
Abstract
Security assurance is a rapidly evolving but well understood discipline in the software industry. Many firms have adopted the Security Development Lifecycle as a process to identify and fix vulnerabilities in their products before they are released. To do this, they rely on sound software security practices, tools and precise technical information available through a vast collection of publicly known vulnerabilities and exploits. Historically, secure development practices for hardware products have not developed as fast. Only a limited number of methodologies, standards, exploits, and testing tools exist to assist vendors with their security assurance goals. This paper presents a Hardware Security Development Lifecycle at the hardware technology level that has been used on commercial CPUs, chipsets, and SoCs. It describes how a structured flow of analysis and testing activities organized in five phases can accelerate the discovery of security issues in computer hardware products that could be exploited through software or physical attacks. We summarize lessons learned over several years of security evaluation experience that have resulted in a systematic method that can be adapted to make security assurance an integral part of hardware development cycles.
Keywords
microprocessor chips; security of data; HSDL; fix vulnerabilities; hardware products; hardware security development lifecycle; hardware technologies; security assurance; security development lifecycle; software industry; sound software security; technical information; Hardware; Microprogramming; Registers; Security; Software; System-on-a-chip; Testing; Hardware Security; Hardware Vulnerabilities; Security Development Lifecycle; Security Validation;
fLanguage
English
Publisher
ieee
Conference_Titel
Hardware-Oriented Security and Trust (HOST), 2012 IEEE International Symposium on
Conference_Location
San Francisco, CA
Print_ISBN
978-1-4673-2341-3
Type
conf
DOI
10.1109/HST.2012.6224330
Filename
6224330
Link To Document