DocumentCode
2137385
Title
Internet Firewalls in the DECOS System-on-a-Chip Architecture
Author
Wasicek, Armin ; Elmenreich, Wilfried
Author_Institution
Vienna Univ. of Technol., Vienna
Volume
2
fYear
2007
fDate
23-27 June 2007
Firstpage
983
Lastpage
988
Abstract
A big part of requests in today´s Internet are malicious connection attempts aimed at compromising hosts in order to gain illegal access. Intrusion tools perform automatic scans to seek out promising targets, probe for vulnerabilities, and even mount autonomous attacks. Outgoing from this scenario, this paper discusses approaches to govern access to a network of System-on-a-Chip (SoC) components that provides an Ethernet interface to the Internet for maintenance purposes. Security measures are needed to protect the SoC from unauthorized access to internal information such as diagnostic interfaces or bus communication. Since the SoC should be realized as a compact embedded system, the implementation of security mechanisms has to fit the available processing and memory resources. In order to be able to cope with changing security requirements and different deployment environments a multi-level security architecture is proposed. The architecture partitions the system into intrusion containment regions and provides corresponding access privileges. As part of the architecture, the implementation of an Internet Firewall providing low level authentication to a network of SoC s is shown.
Keywords
Internet; authorisation; embedded systems; local area networks; message authentication; system buses; system-on-chip; DECOS system-on-a-chip architecture; Ethernet interface; Internet firewall; bus communication; embedded system; illegal access; intrusion detection; malicious connection; multi level security architecture; unauthorized access; Authentication; Communication system security; Embedded system; Ethernet networks; IP networks; Information security; Internet; Probes; Protection; System-on-a-chip; DECOS SOC architecture; Embedded systems security; Time-Triggered Ethernet; firewall;
fLanguage
English
Publisher
ieee
Conference_Titel
Industrial Informatics, 2007 5th IEEE International Conference on
Conference_Location
Vienna
ISSN
1935-4576
Print_ISBN
978-1-4244-0851-1
Electronic_ISBN
1935-4576
Type
conf
DOI
10.1109/INDIN.2007.4384908
Filename
4384908
Link To Document