• DocumentCode
    2137385
  • Title

    Internet Firewalls in the DECOS System-on-a-Chip Architecture

  • Author

    Wasicek, Armin ; Elmenreich, Wilfried

  • Author_Institution
    Vienna Univ. of Technol., Vienna
  • Volume
    2
  • fYear
    2007
  • fDate
    23-27 June 2007
  • Firstpage
    983
  • Lastpage
    988
  • Abstract
    A big part of requests in today´s Internet are malicious connection attempts aimed at compromising hosts in order to gain illegal access. Intrusion tools perform automatic scans to seek out promising targets, probe for vulnerabilities, and even mount autonomous attacks. Outgoing from this scenario, this paper discusses approaches to govern access to a network of System-on-a-Chip (SoC) components that provides an Ethernet interface to the Internet for maintenance purposes. Security measures are needed to protect the SoC from unauthorized access to internal information such as diagnostic interfaces or bus communication. Since the SoC should be realized as a compact embedded system, the implementation of security mechanisms has to fit the available processing and memory resources. In order to be able to cope with changing security requirements and different deployment environments a multi-level security architecture is proposed. The architecture partitions the system into intrusion containment regions and provides corresponding access privileges. As part of the architecture, the implementation of an Internet Firewall providing low level authentication to a network of SoC s is shown.
  • Keywords
    Internet; authorisation; embedded systems; local area networks; message authentication; system buses; system-on-chip; DECOS system-on-a-chip architecture; Ethernet interface; Internet firewall; bus communication; embedded system; illegal access; intrusion detection; malicious connection; multi level security architecture; unauthorized access; Authentication; Communication system security; Embedded system; Ethernet networks; IP networks; Information security; Internet; Probes; Protection; System-on-a-chip; DECOS SOC architecture; Embedded systems security; Time-Triggered Ethernet; firewall;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Industrial Informatics, 2007 5th IEEE International Conference on
  • Conference_Location
    Vienna
  • ISSN
    1935-4576
  • Print_ISBN
    978-1-4244-0851-1
  • Electronic_ISBN
    1935-4576
  • Type

    conf

  • DOI
    10.1109/INDIN.2007.4384908
  • Filename
    4384908