On device identity establishment and verification

  • Authors:
  • Roberto Gallo;Henrique Kawakami;Ricardo Dahab

  • Affiliations:
  • University of Campinas, Campinas, SP, Brazil and KRYPTUS Information Security, Campinas, SP, Brazil;KRYPTUS Information Security, Campinas, SP, Brazil;University of Campinas, Campinas, SP, Brazil

  • Venue:
  • EuroPKI'09 Proceedings of the 6th European conference on Public key infrastructures, services and applications
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

Many high security applications rely ultimately on the security of hardware-based solutions in order to protect both data and code against tampering. For these applications, assuring the device's identity and integrity is paramount. In our work, we explore a number of factors that help to improve on device accreditation, by devising and defining both architectural and procedural requirements related to device construction, shipping and usage. Based on that, we proposed two integrity shared verification schemes which enable regular and auditing users of such applications to promptly and easily verify whether their interfacing hardware is trustworthy. We implemented our solutions in a key application, namely a hardware security module (HSM) suitable for use in supporting PKIs and also showed how it performs equally well in Direct Recording Electronic (DRE) voting machines.