{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T10:05:42Z","timestamp":1768989942456,"version":"3.49.0"},"reference-count":35,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T00:00:00Z","timestamp":1632873600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"EU Horizon 2020 research and innovation programme","award":["739551 (KIOS CoE)"],"award-info":[{"award-number":["739551 (KIOS CoE)"]}]},{"name":"Government of the Republic of Cyprus through the Directorate General for European Programmes, Coordination and Development"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["J. Emerg. Technol. Comput. Syst."],"published-print":{"date-parts":[[2022,1,31]]},"abstract":"<jats:p>Firmware refers to device read-only resident code which includes microcode and macro-instruction-level routines. For Internet-of-Things (IoT) devices without an operating system, firmware includes all the necessary instructions on how such embedded systems operate and communicate. Thus, firmware updates are essential parts of device functionality. They provide the ability to patch vulnerabilities, address operational issues, and improve device reliability and performance during the lifetime of the system. This process, however, is often exploited by attackers in order to inject malicious firmware code into the embedded device. In this article, we present a framework for secure firmware updates on embedded systems. This approach is based on hardware primitives and cryptographic modules, and it can be deployed in environments where communication channels might be insecure. The implementation of the framework is flexible, as it can be adapted in regards to the IoT device\u2019s available hardware resources and constraints. Our security analysis shows that our framework is resilient to a variety of attack vectors. The experimental setup demonstrates the feasibility of the approach. By implementing a variety of test cases on FPGA, we demonstrate the adaptability and performance of the framework. Experiments indicate that the update procedure for a 1183-kB firmware image could be achieved, in a secure manner, under 1.73 seconds.<\/jats:p>","DOI":"10.1145\/3460234","type":"journal-article","created":{"date-parts":[[2021,9,29]],"date-time":"2021-09-29T19:16:42Z","timestamp":1632943002000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["A Modular End-to-End Framework for Secure Firmware Updates on Embedded Systems"],"prefix":"10.1145","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1182-4382","authenticated-orcid":false,"given":"Solon","family":"Falas","sequence":"first","affiliation":[{"name":"University of Cyprus, Nicosia, Cyprus"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Charalambos","family":"Konstantinou","sequence":"additional","affiliation":[{"name":"KAUST, Thuwal, Saudi Arabia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Maria K.","family":"Michael","sequence":"additional","affiliation":[{"name":"University of Cyprus, Nicosia, Cyprus"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2021,9,29]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Haji Akhundov Erik Sluis Said Hamdioui and M. Taouil. 2019. Public-key based authentication architecture for IoT devices using PUF. In CSEIT. 353\u2013371.  Haji Akhundov Erik Sluis Said Hamdioui and M. Taouil. 2019. Public-key based authentication architecture for IoT devices using PUF. In CSEIT. 353\u2013371.","DOI":"10.5121\/csit.2019.91328"},{"key":"e_1_2_1_2_1","unstructured":"Zigbee Alliance. 2019. Zigbee Cluster Library. https:\/\/zigbeealliance.org\/developer_resources\/zigbee-cluster-library\/.  Zigbee Alliance. 2019. Zigbee Cluster Library. https:\/\/zigbeealliance.org\/developer_resources\/zigbee-cluster-library\/."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-48324-4_28"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijcip.2013.04.004"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.3390\/sym10080352"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2832201"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.3390\/cryptography1010003"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2689726"},{"key":"e_1_2_1_9_1","volume-title":"The MITRE Corporation","author":"Vulnerabilities Common","year":"2017","unstructured":"Common Vulnerabilities and Exposures (CVE\u00ae) List , The MITRE Corporation . 2017 . CVE- 2017-5698. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-5698. Common Vulnerabilities and Exposures (CVE\u00ae) List, The MITRE Corporation. 2017. CVE-2017-5698. https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-5698."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671232"},{"key":"e_1_2_1_11_1","volume-title":"When firmware modifications attack: A case study of embedded exploitation. Columbia","author":"Cui Ang","year":"2013","unstructured":"Ang Cui , Michael Costello , and Salvatore Stolfo . 2013. When firmware modifications attack: A case study of embedded exploitation. Columbia , Academic Commons ( 2013 ). Ang Cui, Michael Costello, and Salvatore Stolfo. 2013. When firmware modifications attack: A case study of embedded exploitation. Columbia, Academic Commons (2013)."},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.12.002"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1137\/060651380"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1983.1056650"},{"key":"e_1_2_1_15_1","volume-title":"Hacked: Energy industry\u2019s controls provide an alluring target for cyberattacks","author":"Eaton Collin","year":"2017","unstructured":"Collin Eaton . 2017 . Hacked: Energy industry\u2019s controls provide an alluring target for cyberattacks . http:\/\/www.houstonchronicle.com\/. Collin Eaton. 2017. Hacked: Energy industry\u2019s controls provide an alluring target for cyberattacks. http:\/\/www.houstonchronicle.com\/."},{"key":"e_1_2_1_16_1","volume-title":"2019 IFIP\/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC). IEEE, 198\u2013203","author":"Falas Solon","unstructured":"Solon Falas , Charalambos Konstantinou , and Maria K. Michael . 2019. A hardware-based framework for secure firmware updates on embedded systems . In 2019 IFIP\/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC). IEEE, 198\u2013203 . Solon Falas, Charalambos Konstantinou, and Maria K. Michael. 2019. A hardware-based framework for secure firmware updates on embedded systems. In 2019 IFIP\/IEEE 27th International Conference on Very Large Scale Integration (VLSI-SoC). IEEE, 198\u2013203."},{"key":"e_1_2_1_17_1","volume-title":"Michael","author":"Falas Solon","year":"2019","unstructured":"Solon Falas , Charalambos Konstantinou , and Maria K . Michael . 2019 . Hardware-enabled secure firmware updates in embedded systems. In IFIP\/IEEE International Conference on Very Large Scale Integration-System on a Chip. Springer , 165\u2013185. Solon Falas, Charalambos Konstantinou, and Maria K. Michael. 2019. Hardware-enabled secure firmware updates in embedded systems. In IFIP\/IEEE International Conference on Very Large Scale Integration-System on a Chip. Springer, 165\u2013185."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/MPOT.2015.2490261"},{"key":"e_1_2_1_19_1","volume-title":"Fundamentals of IP and SoC Security","author":"Karri Ramesh","unstructured":"Ramesh Karri , Ozgur Sinanoglu , and Jeyavijayan Rajendran . 2017. Physical unclonable functions and intellectual property protection techniques . In Fundamentals of IP and SoC Security . Springer , 199\u2013222. Ramesh Karri, Ozgur Sinanoglu, and Jeyavijayan Rajendran. 2017. Physical unclonable functions and intellectual property protection techniques. In Fundamentals of IP and SoC Security. Springer, 199\u2013222."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISGTEurope.2017.8260283"},{"key":"e_1_2_1_21_1","volume-title":"The threats to our products. Microsoft Interface","author":"Kohnfelder Loren","year":"1999","unstructured":"Loren Kohnfelder and Praerit Garg . 1999. The threats to our products. Microsoft Interface , Microsoft Corporation 33 ( 1999 ). Loren Kohnfelder and Praerit Garg. 1999. The threats to our products. Microsoft Interface, Microsoft Corporation 33 (1999)."},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/PESGM.2016.7741452"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SmartGridComm.2015.7436314"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.5555\/1509456.1509506"},{"key":"e_1_2_1_25_1","unstructured":"Cyber Independent Testing Lab. 2019. Binary Hardening in IoT products. https:\/\/cyber-itl.org\/2019\/08\/26\/iot-data-writeup.html.  Cyber Independent Testing Lab. 2019. Binary Hardening in IoT products. https:\/\/cyber-itl.org\/2019\/08\/26\/iot-data-writeup.html."},{"key":"e_1_2_1_26_1","volume-title":"Tuya: Revised update process hacked again. https:\/\/www.heise.de\/.","author":"Mocker Andrijan","year":"2019","unstructured":"Andrijan Mocker . 2019 . Tuya: Revised update process hacked again. https:\/\/www.heise.de\/. Andrijan Mocker. 2019. Tuya: Revised update process hacked again. https:\/\/www.heise.de\/."},{"key":"e_1_2_1_27_1","volume-title":"IETF","author":"Moran Brendan","year":"2019","unstructured":"Brendan Moran , Milosch Meriac , Hannes Tschofenig , and David Brown . 2019. A firmware update architecture for Internet of Things devices. Internet-Draft draft-Moran-suit-architecture-02 , IETF ( 2019 ). Brendan Moran, Milosch Meriac, Hannes Tschofenig, and David Brown. 2019. A firmware update architecture for Internet of Things devices. Internet-Draft draft-Moran-suit-architecture-02, IETF (2019)."},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/1715759.1715774"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/JPROC.2014.2331553"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2024724.2024780"},{"key":"e_1_2_1_31_1","unstructured":"Tara Seals. 2019. Mirai Botnet Sees Big 2019 Growth Shifts Focus to Enterprises. https:\/\/threatpost.com\/.  Tara Seals. 2019. Mirai Botnet Sees Big 2019 Growth Shifts Focus to Enterprises. https:\/\/threatpost.com\/."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277206"},{"key":"e_1_2_1_33_1","volume-title":"Build safety of software in 28 popular home routers. Cyber-ITL (Dec","author":"Thompson Parker","year":"2018","unstructured":"Parker Thompson and Sarah Zatko . 2018. Build safety of software in 28 popular home routers. Cyber-ITL (Dec 2018 ). Parker Thompson and Sarah Zatko. 2018. Build safety of software in 28 popular home routers. Cyber-ITL (Dec 2018)."},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/FiCloud.2016.22"},{"key":"e_1_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2019.2926192"}],"container-title":["ACM Journal on Emerging Technologies in Computing Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460234","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3460234","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T20:48:30Z","timestamp":1750193310000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3460234"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,29]]},"references-count":35,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2022,1,31]]}},"alternative-id":["10.1145\/3460234"],"URL":"https:\/\/doi.org\/10.1145\/3460234","relation":{},"ISSN":["1550-4832","1550-4840"],"issn-type":[{"value":"1550-4832","type":"print"},{"value":"1550-4840","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,29]]},"assertion":[{"value":"2020-10-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-04-01","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-29","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}