• DocumentCode
    2523099
  • Title

    Design and Implementation of Secure Embedded Systems Based on Trustzone

  • Author

    Yan-Ling, Xu ; Wei, PAN ; Xin-guo, ZHANG

  • Author_Institution
    Sch. of Autom., Northwestern Polytech. Univ., Xi´´an
  • fYear
    2008
  • fDate
    29-31 July 2008
  • Firstpage
    136
  • Lastpage
    141
  • Abstract
    Embedded system serves as one of crucial components needed for various applications and services in pervasive computing environment. Security problems related to embedded systems directly influence credibility of these applications and services. In order to effectively eliminate weaknesses in current embedded systems and strongly enhance safety practices of these systems, this paper proposes a Trustzone-based secure enhancement framework for embedded system. This framework consists of a multi-policy access control mechanism and a secure reinforcement method. The multi-policy access control mechanism establishes multiple secure policies by utilizing the Domain and Type Enforcement (DTE) model and an improved Bell-La Padula (BLP) model, and the secure reinforcement method provides powerful safeguards through the employment of Linux Security Module (LSM) framework. We construct a secure embedded system environment based on TrustZone technique and secure Linux system. A prototype system founded on ARM Linux achieves rational combination of secure operating system and trustworthy hardware techniques and thus ensures diversified applications and services safety.
  • Keywords
    authorisation; embedded systems; operating systems (computers); ubiquitous computing; ARM Linux; BLP; Bell-La Padula model; DTE; LSM; Linux security module; Trustzone-based secure enhancement framework; domain and type enforcement model; multi policy access control mechanism; pervasive computing; secure embedded systems; secure reinforcement method; Access control; Embedded system; Employment; Linux; Operating systems; Pervasive computing; Power system modeling; Power system security; Prototypes; Safety; Domain and Type Enforcement; Linux Security Module; Mandatory access control; Secure embedded system; TrustZone; Trustworthy hardware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Embedded Software and Systems, 2008. ICESS '08. International Conference on
  • Conference_Location
    Sichuan
  • Print_ISBN
    978-0-7695-3287-5
  • Type

    conf

  • DOI
    10.1109/ICESS.2008.59
  • Filename
    4595549