Hardware Rooted Trust for Additive Manufacturing

Hardware Rooted Trust for Additive Manufacturing
复制标题

增材制造基于硬件的信任

DOI:
--
复制
发表时间:
2019
期刊:
影响因子:
3.9
通讯作者:
Monty Wiseman
Monty Wiseman
中科院分区:
计算机科学3区
文献类型:
--
作者:
D. Safford;Monty Wiseman

文献摘要

被引文献

相似文献

增材制造系统具有独特的安全要求。除了传统的系统完整性之外,增材系统还需要额外的部件真实性和机密性保证。当一个零件从增材制造中出来时,它必须是精确的所需零件,没有替代或篡改。此外,相关文件必须受到严格保护,以防泄露。使用硬件信任根(如可信协议)来保护认证和加密密钥可以保证必要的认证和加密不会被远程软件攻击破坏。例如,如果增材机器用TPM加固,则TPM可以提供加密密钥对,其中私钥永远不会离开硬件。如果零件文件是在相应的公钥下加密的,那么它只能在授权的打印机上解密,并且只有在该打印机的软件没有被破坏的情况下。类似地,部件文件可以由TPM中的私钥签名,并且当由相应的公钥验证时,由硬件确保真实性。本文提供了第一个工作示例,说明如何将此类硬件根源保护集成到现有的增材制造流程中,以显着加强对增材制造文件的真实性,机密性和可用性的保护。
Additive manufacturing systems have unique security requirements. In addition to traditional system integrity, additive systems need additional guarantees of part authenticity and confidentiality. When a part comes out of additive manufacture, it must be the exact desired part, without substitution or tampering. In addition, the associated files must be strongly protected from disclosure. The use of hardware roots of trust like a trusted platform module (TPM) to protect authentication and encryption keys can guarantee that the necessary authentication and encryption cannot be subverted by remote software attack. For example, if the additive machine is hardened with a TPM, the TPM can provide an encryption key pair where the private key never leaves the hardware. If the part file is encrypted under the corresponding public key, then it can only be decrypted on the authorized printer, and only if that printer’s software has not been compromised. Similarly, a part file can be signed by a private key in the TPM, and when validated by the corresponding public key, the authenticity is assured by hardware. This paper provides the first worked examples of how such hardware rooted protections can be integrated into existing additive manufacturing flows to dramatically strengthen protection of the authenticity, confidentiality, and availability of additive manufacturing files.