The NCSC research problem book
Pages
Page 12 of 21
HW3 - Which device architectures help us improve security further up the stack?

Which device architectures help us improve security further up the stack?
Over recent years, the primary use cases for many devices has changed. The rise of cloud computing and edge computing, autonomous vehicles, and the digitisation of critical national infrastructure means that we need not just to understand the security of devices, but also improve the security that a device offers a system. These new use cases often need devices to be architected differently, which can open up new security concerns. So this problem is about how we secure these new device architectures, and whether they offer opportunities to improve security further up the technology stack.
Strands or sub-problems
-
Multi-domain devices
Sharing a processor among multiple users in a cloud environment is a fairly well understood problem, if not perfectly resolved. Less well understood is the use of other devices in a multi-tenant scenario. If a GPU or machine learning accelerator are used by multiple tenants in parallel, how much confidence do we have that a user’s data will be protected? Alternatively, can we partition a device into multiple domains working at different security levels? What could it mean to use physical, logical or temporal separation of domains? In some of these contexts we want to prevent dataflow between domains (tenants in a cloud perhaps), but in others we want deliberate but controlled dataflow. This sub-problem covers both understanding the risks in these architectures, and developing new architectures to mitigate those risks.
-
Novel architectures
Sometimes using a new or alternative architecture can alleviate entire classes of vulnerability, improve the sociotechnical aspects of security (such as ‘secure by design' and ‘secure by default’ concepts), or at the very least make it easier to achieve security goals. We are always interested in identifying and developing new architectures that achieve this, but particularly where there is an achievable route to adoption. This means that research into adoption, or into architectures that don’t create significant incompatibilities with existing systems, is especially interesting. Another approach could be to deliberately engineer significant differences into our architectures, creating deliberate variability, to reduce the risks from any single attack.
Why this is important
“Computing devices are foundational to our increasingly connected lives. If we can improve security of our systems at the device level, this security can carry through and impact our entire society and economy. Where a new device architecture can close off an entire class of vulnerabilities, or secure new use cases, the impact could be profound. Because processors and similar devices are everywhere, improvements here strengthen the foundations of practically every system we rely on.”
Charlie D, Technical Director for Hardware Security, NCSC