As the Internet of Things (IoT) continues to expand, data security has become increasingly important for ensuring privacy and safety, especially given the sensitive and, sometimes, critical nature of the data handled by IoT devices. There exist hardware-based trusted execution environments used to protect data, but they are not compatible with low-cost devices that lack hardware-assisted security features. The research in this paper presents software-based protection and encryption mechanisms explicitly designed for embedded devices. The proposed architecture is designed to work with low-cost, low-end devices without requiring the usual changes on the underlying hardware. It protects against hardware attacks and supports runtime updates, enabling devices to write data in protected memory. The proposed solution is an alternative data security approach for low-cost IoT devices without compromising performance or functionality. Our work underscores the importance of developing secure and cost-effective solutions for protecting data in the context of IoT.
翻译:随着物联网(IoT)的继续扩展,数据安全对于确保隐私和安全越来越重要,特别是考虑到IoT设备处理的数据的敏感性,有时甚至是关键性,存在着用于保护数据的基于硬件的可信赖执行环境,但与缺乏硬件辅助安全功能的低成本装置不兼容。本文件的研究提出了明确为嵌入装置设计的基于软件的保护和加密机制。拟议的结构旨在与低成本、低端装置合作,而不需要对基本硬件进行通常的改动。它保护硬件不受攻击,支持运行时间更新,使装置能够在受保护的记忆中写入数据。提议的解决办法是对低成本的IoT设备采取替代数据安全办法,同时不损害其性能或功能。我们的工作强调了在IoT范围内开发安全且具有成本效益的办法来保护数据的重要性。</s>