Boot to Cloud Security Considerations with IoT.pdf

编号:144791 PDF 33页 1.99MB 下载积分:VIP专享
下载报告请您先登录!

Boot to Cloud Security Considerations with IoT.pdf

1、Boot to Cloud Security Considerations with IoTKevin TownsendZephyr Developer SummitPrague,28 June 2023About MeTech Lead at Linaro,focusing on Arm,RTOS,and IoT Security15 years of full time open source developmentZephyr maintainer for Aarch32,TF-M,zscilibGithub:microbuilderAgendaSecure BootDevice Pro

2、visioningStorage-Free Key DerivationSecuring Data in TransitSecuring Data at RestExample:Confidential AIChecklistCore Components in a Secure IoT SystemSecure BootCore Components in a Secure IoT SystemSecure BootAs the root of trust this is the most critical component in a secure system!Shouldnt be a

3、n afterthought!Test early and test oftenIn the case of Zephyr,this is often MCUBoot,though not alwaysSecure means immutableShould only run valid signed,and ideally versioned imagesMay include rollback protection(MCU_DOWNGRADE_PROTECTION w/MCUBoot)Image contents and signature must be verified every r

4、esetShould support image encryption for safer firmware deliveryMay include limited HW recovery option(serial recovery on GPIO pin on MCUBoot)Secure boot requires protecting the bootloader flash region from overwrites!Must disable SoC device-recovery and debug interfaces on the MCU!MCUBoot:mcumgrMCUB

5、oot CLI management toolMulti transport:Serial,BLE,UDPExtensible command set:Set datetimeUpdate file systemGet thread/device statsReset deviceShell access The optional commands are a double-edged sword and need to be evaluated against your deployment scenario!MCUBoot:imgtoolGenerates correctly-format

6、ted keys$imgtool keygen-k sign_p256.pem-t ecdsa-p256Signs imagesCan be used to verify signaturesGet C-friendly public/private key data:$imgtool getpriv-k sign_p256.pem$imgtool getpub-k sign_p256.pem Always generate and safely store your own private signing key!Point the build system to it via BOOT_S

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(Boot to Cloud Security Considerations with IoT.pdf)为本站 (2200) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠