Protecting devices in the field.
WHAT TO ASSUME
The device is physically accessible to an attacker Firmware can be extracted and analysed Communications can be intercepted
WHAT THAT RULES OUT
Secrets shared across every device Security depending on obscurity Trusting anything the device reports without verification
WHAT PER-DEVICE IDENTITY PROVIDES
Compromise of one device not compromising all.
WHAT TO PROVISION
Unique keys per device, at manufacture.
WHERE TO STORE THEM
A secure element or hardware-protected storage.
WHAT TO DISABLE BEFORE SHIPPING
Debug interfaces Development credentials Verbose logging Unused services
WHY DEBUG INTERFACES SPECIFICALLY
They frequently provide complete access, and are routinely left enabled.
WHAT TO ENCRYPT
Stored data, and all communications.
WHAT TO VALIDATE
Every input, including from sensors and peripherals.
WHY
Malformed input has been used to compromise devices.
WHAT TO PLAN FOR
Vulnerability disclosure, and how you would respond.
WHAT OBLIGATIONS MAY APPLY
Regulations increasingly require update capability and disclosure processes.
Take advice on your position.