ARM-PSA Embedded Hardware Threat Model for Onboard Controller of Cubesatellite
摘要
This paper discusses the Threat model design of the onboard controller of Cubesatellite. The threat model design proposed in the paper is based on ARM-Platform Security Architecture (ARM-PSA) with the foundation of Common Criteria (CC) standard ISO/IEC 15408 and Microsoft’s STRIDE framework addressing critical security principles such as Authentication, Authorization, Repudiation, Confidentiality, Integrity, and Availability (CIA) Triad. The intention behind the selection of the ARM-PSA framework for designing the threat model is to address embedded security challenges such as threats to the micro-controller, embedded communication, hardware, firmware, and other peripherals associated with the onboard controller of cubesatellite. The minimalist hardware architecture for the onboard controller of a cubesatellite considered in the scope consists of a microcontroller, memory, and sensors. To counter the threats identified during threat modeling, the paper proposes security objectives against each threat, followed by a threat entry vector. This paper also addresses threats by side-channel attacks and fault injection attacks. The paper also proposes hardware exploit security threats not mentioned in ARM-PSA and adds hardware defense as a security objective to counter the same. Thus, it provides better coverage of threats in the ARM-PSA framework.