Skip to main navigation Skip to search Skip to main content

An embedded key management system for PUF-based security enclosures

  • Johannes Obermaier
  • , Florian Hauschild
  • , Matthias Hiller
  • , Georg Sigl
  • Fraunhofer AISEC

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

10 Scopus citations

Abstract

Hardware Security Modules (HSMs) are embedded systems which provide a physically secured environment for data storage and handling. The device is protected by an enclosure against adversaries. A supervisor circuit monitors the enclosure's integrity and deletes all Critical Security Parameters (CSPs), such as keys, upon a tamper event. While current solutions store CSPs in battery-backed memory, our novel batteryless solution exploits the Physical Unclonable Function (PUF) of the enclosure to derive a key encryption key (KEK). However, such a PUF-based solution requires a more complex Embedded Key Management System (EKMS) for integrity verification, PUF usage, and key management. In this paper, we address this issue by discussing an adversary model, deriving design requirements, and presenting a hardened firmware architecture for PUF-based security enclosures. We present the complementing security extensions for FreeRTOS that enhance the operating system's security. To verify the concept's feasibility, we implement the proposed system and evaluate its performance. Our results show that this security architecture for an EKMS can serve as a firmware basis for novel PUF-based HSMs.

Original languageEnglish
Title of host publication2018 7th Mediterranean Conference on Embedded Computing, MECO 2018 - Including ECYPS 2018, Proceedings
EditorsLech Jozwiak, Budimir Lutovac, Drazen Jurisic, Radovan Stojanovic
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1-6
Number of pages6
ISBN (Electronic)9781538656822
DOIs
StatePublished - 6 Jul 2018
Event7th Mediterranean Conference on Embedded Computing, MECO 2018 - Budva, Montenegro
Duration: 10 Jun 201814 Jun 2018

Publication series

Name2018 7th Mediterranean Conference on Embedded Computing, MECO 2018 - Including ECYPS 2018, Proceedings

Conference

Conference7th Mediterranean Conference on Embedded Computing, MECO 2018
Country/TerritoryMontenegro
CityBudva
Period10/06/1814/06/18

Keywords

  • Embedded System
  • FIPS140-2
  • Firmware Architecture
  • HSM
  • Key Management
  • PUF
  • RTOS
  • Security Enclosure

Fingerprint

Dive into the research topics of 'An embedded key management system for PUF-based security enclosures'. Together they form a unique fingerprint.

Cite this