Platform Embedded Security Technology Revealed
Xiaoyu Ruan · Apress eBooks · 2014
Cyber Security in the Mobile AgeThe number of new security threats identified every month continues to rise.We have concluded that security has now become the third pillar of computing, joining energy-efficient performance and Internet connectivity in importance. -Paul S. OtelliniThis book is an in-depth technical introduction to an embedded system developed and manufactured by Intel Corporation.The embedded system is not an independent product; it is a native ingredient inside most of Intel's computer product portfolio, which includes servers, desktops, workstations, laptops, tablets, and smartphones.Although not well known to most end users, the embedded system plays a critical role in many consumer applications that people use every day.As such, its architecture, implementation, and security features are worth studying.Depending on the end product in which the embedded engine resides, the engine is denominated differently: For the embedded system shipped with computing devices • featuring Intel Core family microprocessors, it is called the management engine.For the embedded system shipped with computing devices • featuring the Intel Atom system-on-chip (SoC), it is called the security engine.Note that not all Atom platforms use the security engine introduced in this book.For the sake of convenience, this book refers to it as the security and management engine, the embedded engine, or simply the engine.Security validation is a pivotal stage in software development.A vendor with a good quality control system should apply proven techniques, such as static code analysis, penetration testing, and so forth, to their product development life cycle.Even though the third-party software has been tested for security by its vendor, in many cases it is still worth it for the adopter to conduct independent code review and end-to-end validations, either in-house or by hiring specialized security auditing firms.This is necessary especially for modules that process sensitive data. Note ■Consider performing comprehensive security validation and auditing for open-source and third-party software. Security Development LifecycleThe Security Development Lifecycle, or SDL, is a process consisting of activities and milestones that attempt to find and fix security problems during the development of software, firmware, or hardware.The SDL is extensively exercised by technology companies, for example, Microsoft and Intel.Different companies decide their specific procedures and requirements for SDL, but they all aim at the same goal: to produce high-quality products with regard to security and to reduce the cost of handling aftermaths for vulnerabilities found after release.Intel is committed to securing its products and customers' privacy, secrets, and assets.To build a solid third pillar for computing, a sophisticated SDL procedure of five stages is implemented at Intel to make security and privacy an integral part of product definition, design, development, and validation:• Assessment: Determine what SDL activities are applicable and will be performed.• Architecture review: Set security objectives, list a threat analysis, and design corresponding mitigations.• Design review: Map security objectives to low-level design artifacts.Make sure designs meet security requirements.• Development review: Conduct a comprehensive code review to eliminate security vulnerabilities, such as buffer overflow.• Deployment review: Perform security-focus validation and penetration testing and assure that the product is ready for release, from both the privacy and security perspectives.The SDL process applies to hardware, firmware, and software, with small differences in different stages.Intel takes users' privacy seriously.The privacy aspect is called out in the SDL process and evaluated separately, in parallel with the technical aspect of security, throughout all the five phases.Figure 1-2 shows the SDL phases and components.A product may ship only after the deployment privacy and security review has been accomplished and approved.