• DocumentCode
    626331
  • Title

    Software-Based Remote Attestation for Safety-Critical Systems

  • Author

    Preschern, Christopher ; Hormer, Andreas Johann ; Kajtazovic, Nermin ; Kreiner, Christian

  • Author_Institution
    Inst. for Tech. Inf., Graz Univ. of Technol., Graz, Austria
  • fYear
    2013
  • fDate
    18-22 March 2013
  • Firstpage
    8
  • Lastpage
    12
  • Abstract
    Assuring system integrity to a remote communication partner through attestation is a security concept which also is very important for safety-critical systems facing security threats. Most remote attestation methods are based on integrity measurement mechanisms embedded in the underlying hardware or software (e.g. operating system). Alternatively, the application software can measure itself, whereas the security of this approach relies on obscurity of the measurement mechanism. There are several tools available to introduce such obscurity through automatic code transformations, but these tools cannot be applied to safety-critical systems, because automatic code transformations are difficult to justify during safety certification. We present a software-based remote attestation concept for safety-critical systems and apply it to an automation system case study. The attestation concept utilizes the safety-related black channel principle to allow the application of code protection tools in order to protect the attestation mechanism without increasing the safety certification effort for the system.
  • Keywords
    safety-critical software; security of data; application software; attestation concept; attestation mechanism; code protection tool; code transformation; integrity measurement mechanism; safety certification; safety-critical system; safety-related black channel principle; security concept; security threat; software-based remote attestation; system integrity; Automation; Conferences; Cryptography; Safety; Software; Software measurement; IEC 61508; black channel; functional safety; software-based remote attestation;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Testing, Verification and Validation Workshops (ICSTW), 2013 IEEE Sixth International Conference on
  • Conference_Location
    Luxembourg
  • Print_ISBN
    978-1-4799-1324-4
  • Type

    conf

  • DOI
    10.1109/ICSTW.2013.7
  • Filename
    6571600