An organization is establishing hardware security specifications for edge computing appliances deployed in remote, physically untrusted locations. The security architect must ensure cryptographic keys stored on hardware cannot be extracted via physical chip probing, and device identities cannot be duplicated onto unauthorized hardware. Which of the following hardware security controls should be implemented to meet these specific requirements? (Select TWO.)
- Physically Unclonable Functions (PUF) to generate unique cryptographic keys derived from semiconductor manufacturing variationsCevap
- Cryptographic co-processor with active physical tamper detection integrated to trigger key zeroization upon enclosure breachCevap
- CHost-based Intrusion Prevention System (HIPS) to monitor raw memory addresses and restrict physical bus read requests
- DUnprotected non-volatile flash storage configured with high-speed symmetric AES key tables for boot acceleration
Cevap
Implementing Physically Unclonable Functions (PUF) to derive unique key material from silicon manufacturing variations, and deploying active tamper-detection mechanisms integrated with cryptoprocessors to zeroize keys upon physical breach.
Physically Unclonable Functions (PUF) utilize unique manufacturing variations in semiconductor silicon to generate distinct cryptographic key material that cannot be cloned across devices. Active tamper detection mechanisms paired with cryptoprocessors provide physical protection by detecting enclosure compromises and immediately zeroizing sensitive keys to prevent extraction via physical probing.
Adım Adım Çözüm
Anahtar Kavram
Hardware-Based Key Protection and Anti-Tamper Mechanisms