A hacked smart thermostat or a compromised industrial sensor can bring down an entire network—SIPP aims to stop that by redesigning the security of the processor chips inside Internet of Things (IoT) devices from the ground up. Most IoT devices are cheap, low-power, and have limited memory and computing power, which makes them vulnerable. Manufacturers often rush products to market without building in security, leaving devices open to cloning, hacking, or malicious modification. The consequences range from leaked personal data to loss of control over safety-critical infrastructure such as power grids or water treatment systems. Recent attacks like Spectre and Meltdown have shown that even the fundamental design of a processor’s internal components can be exploited. SIPP will re-engineer processor architecture at multiple levels: securing individual on-chip components, authenticating entire chips to detect tampering, and developing remote attestation methods to verify the integrity of boards and systems. The team will also test for physical leakage of secrets at each layer. If successful, the project could make IoT networks—from home devices to national infrastructure—far more trustworthy without requiring expensive hardware upgrades. The work builds on the RISC-V open-source architecture, which could allow the security methods to be widely adopted.
View original technical description
As the world becomes ever more connected, the vast number of Internet of things (IoT) devices necessitates the use of smart, autonomous machine-to-machine communications; however, this poses serious security and privacy issues as we will no longer have direct control over with what or whom our devices communicate. Counterfeit, hacked, or cloned devices acting on a network can have significant consequences: for individuals through the leakage of confidential and personal information, in terms of monetary costs (for e.g. the loss of access to web services - Mirai attack on Dyn took down Twitter, Spotify, Reddit); or for critical national infrastructure, through the loss of control of safety-critical industrial and cyber-physical IoT systems. In addition, IoT devices are often low-cost, low power devices that are restricted in both memory and computing power. A major challenge is how to address the need for security in such resource-constrained devices. As companies race to get IoT devices to market, many do not consider security or, all too often, security is an afterthought. As such, a common theme in all realms of IoT is the need for dependability and security. The SIPP project aims to rethink how security is built into IoT processor platforms. Firstly, the architectural fundamentals of a processor design need to be re-engineered to assure the security of individual on-chip components. This has become increasingly evident with the recent Spectre and Meltdown attacks. On the upper layer of systems-on-chip (SoCs), hardware authentication of chip sub-systems and the entire chip is crucial to detect malicious hardware modification. Then, at the systems layer (i.e., multiple chips on a common printed circuit board), innovative approaches for remote attestation will be investigated to determine the integrity at board level. Finally, the security achieved at all hierarchical layers will be assessed by investigating physical-level vulnerabilities to ensure there is no physical leakage of the secrets on which each layer relies. The proposed project brings together the core partners of the NCSC/EPSRC-funded Research Institute in Secure Hardware and Embedded Systems (RISE), that is, Queen's University Belfast and the Universities of Cambridge, Bristol and Birmingham, with the leading academics in the field of hardware security and security architecture design from the National University of Singapore and Nanyang Technological University, to develop a novel secure IoT processor platform with remote attestation implemented on the RISC-V architecture.
Daniel Page (Co-Investigator)David Oswald (Co-Investigator)Mark Ryan (Co-Investigator)Máire O'Neill (Principal Investigator)Robert Watson (Co-Investigator)Simon Moore (Co-Investigator)
Plain English summaries and category classifications on this site are generated by AI and may not perfectly reflect the original research.
Is something wrong? Let us know