Advanced search
Start date
Betweenand

An architectural proposal integrating the SPDM standard for embedded systems attestation

Grant number: 24/02960-6
Support Opportunities:Scholarships in Brazil - Master
Start date: April 01, 2024
End date: December 31, 2025
Field of knowledge:Engineering - Electrical Engineering
Agreement: MCTI/MC
Principal Investigator:Marcos Antonio Simplicio Junior
Grantee:Otávio Felipe de Freitas
Host Institution: Escola Politécnica (EP). Universidade de São Paulo (USP). São Paulo , SP, Brazil
Company:Secretaria de Desenvolvimento Econômico (São Paulo - Estado). Instituto de Pesquisas Tecnológicas S/A (IPT)
Associated research grant:20/09850-0 - Applied Artificial Intelligence Research Center: accelerating the evolution of industries toward standard 5.0, AP.PCPE

Abstract

The number of embedded devices connected to the Internet of Things network grows annually. Concurrently, the necessity to protect these devices against a vast variety of attacks also grows. Especially, scenarios in which attackers have physical access to critical components along the production chain or their field operation induce a concern, an inherent characteristic of these industrial embedded devices 4.0. To answer this concern, a group formed by many hardware manufacturers recently proposed the open industrial standard named Security Protocol and Data Model (SPDM). Essentially, this solution allows single components of a computer system (e.g., memories, ethernet cards, processors, etc.) to verify mutually their authenticity and establish secure communication channels protected by cryptography. However, the SPDM still hasn't been widely implemented and tested in vast application scenarios for its recent proposal. Particularly, the proposed research project's objective consists of enabling the SPDM use in a relevant scenario that, to our best knowledge, is still not explored in the literature: building an architecture integrating the SPDM to the BIOS' Unified Extensible Firmware Interface (UEFI) to enable secure boot, components verification, and secure communication establishment among them since the moment the device is initialized. Thus, the study must evaluate the viability of this integration as well as the computational costs, comparing the benefits and limitations observed regarding the alternative methods of protection in the literature.

News published in Agência FAPESP Newsletter about the scholarship:
More itemsLess items
Articles published in other media outlets ( ):
More itemsLess items
VEICULO: TITULO (DATA)
VEICULO: TITULO (DATA)