Securing resource-constrained Industrial Internet of Things (IIoT) devices requires guarantees of integrity and confidentiality. This paper presents a security framework developed under the CERTIFY project to document and justify trustworthy execution of sensitive software running on resource-constrained devices. Our architecture model assumes the presence of a separation kernel, that employs hardware Memory Protection Units to enforce Memory isolation and mediate communications during boot, provisioning, and run-time. On the other side, the paper does not cover implementation aspects, but leaves them to the choice of the user intending to adopt the proposed solution architecture. To systematically show the trustworthiness of this proposed architecture, we develop an assurance case using Goal Structuring Notation: we map system requirements to architecture-specific security objectives and introduce a novel “attacker action” graphical element to explicitly integrate threat modeling into our arguments. The resulting assurance case provides a structured, auditable, and reusable foundation architecture for the secure implementation of the CERTIFY IIoT framework.
Building similarity graph...
Analyzing shared references across papers
Loading...
Valerio Senni
Simone Fulvio Rollini
Fabio Federici
Collins College
Electronics
Collins College
Building similarity graph...
Analyzing shared references across papers
Loading...
Senni et al. (Mon,) studied this question.
synapsesocial.com/papers/69c37b41b34aaaeb1a67d86b — DOI: https://doi.org/10.3390/electronics15061337