5 ms·
Perhaps you can adapt "Diverse Double-Compiling" to "Diverse Double-Manufacturing"? http://www.dwheeler.com/trusting-trust/ http://www.dwheeler.com/trusting-tru
by pjtr 11y ago
Perhaps you can adapt "Diverse Double-Compiling" to "Diverse Double-Manufacturing"?
http://www.dwheeler.com/trusting-trust/ http://www.dwheeler.com/trusting-trust/
- Jach 11y agoI had the same thought. I think the hardest part could be "diffing" the outputs, though. Is some particular difference within expected parameters, or can you really detect that hidden bit of metal on layer 5 of the board? Interestingly I stumbled upon this: http://www.sandia.gov/mstc/fabrication/index.html http://www.sandia.gov/mstc/fabrication/index.html
- nickpsecurity 11y agoDidn't know they had a rad-hard, S-ASIC offering. Thanks for the link.
- nickpsecurity 11y agoThat's not going to happen because the two toolchains won't be anything alike. You won't be able to make them alike either. Worse, that people often quote Thompson's attack shows that INFOSEC teaches subversion very poorly: it's the least likely attack to affect you and you really need to counter the others. What you have to do is make the software correct, make it secure, and ensure no subversion in lifecycle. That's called high assurance or robustness system design. Links below show you how to do that. High assurance software design - nice intro http://web.cecs.pdx.edu/~hook/cs491sp08/AssuranceSp08.ppt http://web.cecs.pdx.edu/~hook/cs491sp08/AssuranceSp08.ppt FOSS tools for high assurance http://www.dwheeler.com/essays/high-assurance-floss.html http://www.dwheeler.com/essays/high-assurance-floss.html Certified compilation (HW w/ need certified "synthesis") http://compcert.inria.fr/ http://compcert.inria.fr/ Original work on subversion http://csrc.nist.gov/publications/history/myer80.pdf http://csrc.nist.gov/publications/history/myer80.pdf Example of it in action http://www.cisr.us/downloads/theses/02thesis_anderson.pdf http://www.cisr.us/downloads/theses/02thesis_anderson.pdf Example of high assurance hardware (AAMP7G version is secure but no public paper...) http://www.csl.sri.com/papers/wift95/wift95.pdf http://www.csl.sri.com/papers/wift95/wift95.pdf