Developing an Applied, Security-oriented Computing Curriculum

Marcin Łukowiak, Andrew Meneely, Stanisław Radziszowski, James R. Vallino, Christopher A. Wood · 2020

Abstract Developing an Applied, Security-Oriented Computing CurriculumSoftware and hardware security is a reality that all stakeholders must face, from hardwareengineers to software developers to customers. As a direct result, the technology industry isfacing a growing need for graduates who have an understanding of security principles at varyinglevels of abstraction. These graduates will need security-oriented perspectives stemming fromboth theoretical and practical disciplines, including Software Engineering, ComputerEngineering, and Computer Science. Unfortunately, in traditional academic settings, securesoftware and hardware are typically taught by separate departments despite being intertwined inpractice. Consequently, the objective of this initiative is to prepare students to apply a security-oriented awareness to every aspect of hardware and software systems by developing a multi-disciplinary curriculum involving three departments. Our efforts focus on integrating securityinto software design and implementations, hardware design and implementations, and hardware-software co-design. In this paper, we describe changes we made to an existing introductorycryptography course, report on a recently-developed course entitled “Hardware and SoftwareDesign for Cryptographic Applications”, and present our plans for a “Secure SoftwareEngineering” course.For several years, we have been offering coursework in cryptography in the Department ofComputer Science. Cryptography I, a traditional introductory course, covers block ciphers, hashfunctions, and public-key systems together with the mathematics behind it. In the last offering ofCryptography I, we introduced a new thread on efficiency and secure implementations ofcryptographic algorithms. This new material encourages students to enroll in one or both of thenew courses discussed below.The goal of the “Hardware and Software Design for Cryptographic Applications” is to buildknowledge and skills necessary for efficient and secure implementations of cryptographicprimitives on reconfigurable hardware. The implementation platform is a field programmablegate array (FPGA) containing a general purpose processor and additional reconfigurable fabricfor implementations of custom hardware accelerators. Student teams design selectedcryptographic primitives followed by comparison and contrast of various implementationalternatives, such as software, custom FPGA hardware, and hybrid hardware-software co-design.Project teams are ideally composed of one Computer Engineering student and one Software Engineeringor Computer Science student. Topics include: binary finite field arithmetic, block ciphers, hashfunctions, modes of operation for block ciphers, public key cryptosystems, hardware-softwareco-design methodologies with FPGAs, software development and profiling, high level synthesis,FPGA-based embedded system architectures, hardware/software interfaces, and customhardware accelerators.The goal of the “Secure Software Engineering” course is to equip students for applying securityprinciples to every phase of the software development lifecycle. Topics include: threat modeling,risk analysis, secure requirements, secure designs, defensive coding techniques, cryptographicalgorithm deployment, penetration testing, static source code analysis, and security assessment.Students will learn sound security fundamentals by conducting case studies on real-worldsoftware and by using cutting-edge tools and technologies.

Read the paper · More papers on PaperTik