Soru

Zorluk: OrtaHardware and Embedded Systems Security

A security engineer is designing an embedded industrial sensor node deployed in untrusted physical locations. The design requires that the system only executes cryptographically signed boot code during power-on to prevent unauthorized firmware modifications. Which of the following hardware security controls should the engineer implement to fulfill this requirement?

  1. Hardware Root of Trust with Secure BootCevap
  2. B
    Host-based Intrusion Prevention System software agent
  3. C
    High-speed symmetric AES encryption of sensor payload data at rest
  4. D
    Application-level audit logging configured to capture runtime error events

Cevap

Hardware Root of Trust with Secure Boot
The combination of a Hardware Root of Trust and Secure Boot anchors security in immutable read-only memory (such as internal boot ROM or eFuses). During device bootup, the hardware Root of Trust cryptographically verifies the digital signature of the bootloader before executing it, ensuring that altered or untrusted firmware cannot run.

Adım Adım Çözüm

1
Analyze the hardware security requirement
The scenario requires ensuring that only cryptographically signed boot code runs at startup to prevent unauthorized firmware modification on an embedded device.
Embedded hardware in untrusted physical environments requires cryptographic validation of firmware before execution.
2
Evaluate hardware-based security controls
Secure Boot anchored in a hardware Root of Trust uses immutable boot ROM keys to verify the signature of the bootloader image.
This establishes a cryptographically validated chain of trust from initial hardware power-on through operating system execution.
3
Differentiate from software, cryptographic payload, or detective controls
Software agents, data-at-rest encryption, and logging operate post-boot or focus on confidentiality rather than early boot signature validation.
Hardware boot verification must occur prior to any software-level control execution.

Anahtar Kavram

Hardware Root of Trust and Secure Boot
Tahmini Süre:1m 15s
Bu soruyu puanla