Current firmware update workflows are geared towards ensuring integrity and confidentiality in the face of untrusted servers mediating the communication process. However, they cannot ensure that the update’s content preserves deployment-specific security properties, potentially allowing vulnerabilities or malicious code if third-party components compromise or alter the firmware. There is also no guarantee that the new firmware retains the old one’s security properties, a crucial requirement in safety-critical environments. We propose an enhancement of the SUIT standard which ensures that software updates preserve a formally-specified set of behavioral properties in the affected components. We demonstrate the feasibility of the proposed workflow in some realistic use cases.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Certified Secure Updates for IoT Devices

  • Alberto Tacchella,
  • Emanuele Beozzo,
  • Bruno Crispo,
  • Marco Roveri

摘要

Current firmware update workflows are geared towards ensuring integrity and confidentiality in the face of untrusted servers mediating the communication process. However, they cannot ensure that the update’s content preserves deployment-specific security properties, potentially allowing vulnerabilities or malicious code if third-party components compromise or alter the firmware. There is also no guarantee that the new firmware retains the old one’s security properties, a crucial requirement in safety-critical environments. We propose an enhancement of the SUIT standard which ensures that software updates preserve a formally-specified set of behavioral properties in the affected components. We demonstrate the feasibility of the proposed workflow in some realistic use cases.