官术网_书友最值得收藏!

Implementation

During implementation, the actual product is coded and/or manufactured, and integrated according to the design documents. Engineering Change Proposals (ECPs) are used when needed to modify requirements and designs, which then flow back into the implementation phase.

Developers must work with security engineers to code software and configure hardware to meet security requirements. Security engineers should aid developers by publishing secure coding guidelines, and configuring Continuous Integration (CI) tools to look for bugs in software.

Security engineers should also regularly run static and dynamic code analysis tools, and feed data from those tools back into the development process.

They should also work on creating test drivers or emulators that exercise functionality. For example, creating an emulator that emulates the instantiation of a secure connection (such as TLS) and the authentication between devices would provide developers with confidence that each device is operating according to defined security requirements.

Emulators can be a great tool for developers of IoT products and systems. The author participated in a proof of concept for the connected vehicle Security Credential Management System ( SCMS),  where his team created an emulator of the On-Board Equipment (OBE) to be installed within connected vehicles. This OBE emulator was developed to the appropriate cryptographic specifications, and provided the development team with a way to test their interfaces during each release of the system. This was important for testing the bootstrap and enrollment processes of the SCMS. 
主站蜘蛛池模板: 迁西县| 沧州市| 辽中县| 慈溪市| 南充市| 济南市| 甘孜县| 虎林市| 沂水县| 大足县| 武山县| 崇信县| 舞阳县| 巴南区| 荣昌县| 义马市| 双鸭山市| 东莞市| 红安县| 安溪县| 河源市| 齐齐哈尔市| 长治市| 黎平县| 揭阳市| 临海市| 巩留县| 华亭县| 民县| 东城区| 会昌县| 乌审旗| 巴东县| 江达县| 固安县| 赤壁市| 苍溪县| 康保县| 卫辉市| 新竹市| 白山市|