Digital Security by Design: A Review of Combined Hardware-Software-Based CyberSecurity with Compartmentalization
Rabia Khan, Kinan Ghanem, Federico Coffele · 2023
Compartmentalization serves as a cornerstone for fortified hardware and software security. This technique encompasses memory isolation, trusted execution environments, and hardware-based security mechanisms. Software compartmentalization includes sandboxing, virtualization, microservices, and code isolation, collectively mitigating security breaches and vulnerabilities while enhancing resilience. Uniquely, this paper introduces the innovative fusion of the Morello board, distinguished for fine-grained compartmentalization, with CheriBSD. Positioned within the convergence of Operational Technology (OT) and Information Technology (IT), Morello bridges Real-Time Digital Simulators (RTDS) and Intelligent Electronic Devices (IEDs)/sensors. By orchestrating previously unexplored territory, this work underscores the novel potential of Morello and CheriBSD in fortifying security for OT/IT integration, yielding unprecedented outcomes in the realm of cybersecurity.