Security Evaluation of Smart Cards and Secure Tokens: Benefits and Drawbacks for Reducing Supply Chain Risks of Nuclear Power Plants
- Sandia National Laboratories (SNL), Albuquerque, NM, and Livermore, CA (United States)
The supply chain attack pathway is being increasingly used by adversaries to bypass security controls and gain unauthorized access to sensitive networks and equipment (e.g., Critical Digital Assets). Cyber-attacks targeting supply chain generally aim to compromise the environments, products, or services of vendors and suppliers to inject, add, or substitute authentic software and hardware with malicious elements. These malicious elements are deemed to be authentic as they arise from the vendor or supplier (i.e., the supply chain). This research aims to leverage findings and assumptions made from the previous report to determine the security benefits and drawbacks of a smart card- based hardware root of trust. Smart cards can provide devices inside Nuclear Power Plants (NPP) with a secure environment to store keys in and perform sensitive operations such as digital signature generation. These abilities can be leveraged to increase supply chain cybersecurity by autonomously providing NPP Licensees with reports on device integrity, authenticity and measurements of executable and non-executable data.
- Research Organization:
- Sandia National Laboratories (SNL-NM), Albuquerque, NM (United States)
- Sponsoring Organization:
- USDOE Office of Nuclear Energy (NE); USDOE National Nuclear Security Administration (NNSA)
- DOE Contract Number:
- NA0003525
- OSTI ID:
- 1884928
- Report Number(s):
- SAND2022-11359; 709389
- Country of Publication:
- United States
- Language:
- English
Similar Records
A Review of Technologies that can Provide a 'Root of Trust' for Operational Technologies
Authentication techniques for smart cards
Towards a New Supply Chain Cybersecurity Risk Analysis Technique
Technical Report
·
Mon Feb 28 23:00:00 EST 2022
·
OSTI ID:1861944
Authentication techniques for smart cards
Conference
·
Mon Jan 31 23:00:00 EST 1994
·
OSTI ID:10141490
Towards a New Supply Chain Cybersecurity Risk Analysis Technique
Technical Report
·
Sat Jul 31 20:00:00 EDT 2021
·
OSTI ID:1877401