New Technical Guide: Physical Protection Mechanisms for Embedded Systems
We are pleased to share the publication of a new technical guide (STIG) dedicated to physical protection mechanisms for embedded systems.
This guide formalizes a set of technical requirements applicable to the design and cybersecurity assessment of embedded equipment based on SoC, microcontroller, or FPGA. It covers the hardware and software chain, from physical access to the equipment down to secure boot mechanisms.
Each requirement is mapped to a minimum expected attacker level, using the Common Criteria AVA_VAN scale (Basic, Enhanced-Basic, Moderate, High), so that protection choices can be justified against a realistic and auditable threat model.
Reference Threats
The guide is built around four reference threats that recur throughout the analysis:
- unauthorized opening of the enclosure
- extraction or replacement of components
- abuse of debug and test interfaces
- compromise of update or boot mechanisms
Guide Objectives
The guide aims to:
- cover physical and logical interfaces accessible in a laboratory context
- describe physical protection countermeasures, including seals, sensors, and erasure mechanisms
- detail software trust mechanisms such as secure boot, TEE, and operational/security maintenance
- associate each requirement with the attacker profile it is designed to resist
It provides an operational summary with guiding principles and a prioritization of actions, so that teams with limited resources can focus first on the countermeasures with the highest impact.
Download the Guide
English version: Download Technical Guide (PDF)
French version: Télécharger le guide technique (PDF)
The document is published under a Free License.