13.07.2015 Views

System Architecture Design

System Architecture Design

System Architecture Design

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

pSHIELD<strong>System</strong> <strong>Architecture</strong> <strong>Design</strong>Anti-replay protection should protect against denial of service attacks (20034).PUIPSecThere should be applicability of IPSec at network layer (20039).WS-SecurityThere should be applicability of Web Services security at Middleware layer (20045).Security AgentThe formulation and function of Security Agent encapsulates pSHIELD platform and scope. It is a modulethoroughly described throughout pSHIELD study (2302).Miscellaneous/Secure functionalitiesFunctionalities should be performed in a secure way: firmware upgrade, boot (01005, 01006).5.2 <strong>System</strong> <strong>Architecture</strong> Privacy RequirementsPrivacyData should be accessed only by authorized users (0303).Privacy at Power NodeThe FPGA engine should include a core logic that encrypts any sensitive data prior to transmitting itacross the network or storing it on the embedded storage. Also, in the privacy chain BIOS passwordprotection should be included (09009, 09010).Asymmetric cryptographyA node should have a HW implementation of asymmetric cryptography (01033).5.3 <strong>System</strong> <strong>Architecture</strong> Dependability RequirementsIntegrityThe system should be able to prevent improper alterations (20043).ESs integration/expansionIn case of addition of new ESs in the system, it should be possible to easily evaluate the impact of themodification on the overall system dependability (0305).Mechanism for failure mitigationThe pSHIELD system should provide robust mechanisms to mitigate the effects on the system of thefollowing logical threats: software failures, hardware failures, transmission failures (0307, 0308).Trusted and dependable connectivityThe pSHIELD system shall allow trusted and dependable connectivity (20014).Usability of ESs devicesMiddleware of the pSHIELD system should enable any embedded device to be usable from a pSHIELDapplication (20025).AvailabilityA pSHIELD node should be designed with mechanisms that improve system availability (e.g. middlewareservice discovery functionality should list node and network services) (01014, 0703).PUD2.3.2Issue 5 Page 64 of 122

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!