An Evidence-Based Curriculum Initiative for Hardware Reverse Engineering Education
收藏osf.io2024-11-08 更新2025-01-09 收录
下载链接:
https://osf.io/dt8ne
下载链接
链接失效反馈官方服务:
资源简介:
This repository holds the underlying search data of our literature review, as well as extended information on the discovered hardware security and hardware reverse engineering courses.
Paper Abstract: The increasing importance of supply chain security for digital devices—from consumer electronics to critical infrastructure—has created a high demand for skilled cybersecurity experts. These experts use Hardware Reverse Engineering (HRE) as a crucial technique to ensure trust in digital semiconductors. Recently, the US and EU have provided substantial funding to educate this cybersecurity-ready semiconductor workforce, but success depends on the widespread availability of academic training programs. In this paper, we investigate the current state of education in hardware security and HRE to identify efficient approaches for establishing effective HRE training programs. Through a systematic literature review, we uncover 13 relevant courses, including eight with accompanying academic publications. We identify common topics, threat models, key pedagogical features, and course evaluation methods. We find that most hardware security courses do not prioritize HRE, making HRE training scarce. While the predominant course structure of lectures paired with hands-on projects appears to be largely effective, we observe a lack of standardized evaluation methods and limited reliability of student self-assessment surveys. Our results suggest several possible improvements to HRE education and offer recommendations for developing new training courses. We advocate for the integration of HRE education into curriculum guidelines to meet the growing societal and industrial demand for HRE experts.
本存储库汇集了我们文献综述的底层搜索数据,以及关于发现的硬件安全与硬件逆向工程课程的扩展信息。
论文摘要:随着数字设备,从消费电子产品到关键基础设施,供应链安全重要性的日益凸显,对于熟练的网络安全专家的需求急剧上升。这些专家将硬件逆向工程(HRE)视为确保数字半导体信任的关键技术。近期,美国和欧盟提供了大量资金用于培养具备网络安全技能的半导体劳动力,但成功取决于学术培训计划的广泛可获取性。在本研究中,我们探讨了硬件安全与HRE教育的当前状态,以识别建立有效HRE培训计划的效率方法。通过系统性的文献综述,我们发现了13门相关课程,其中包括八门附带学术出版物。我们确定了常见主题、威胁模型、核心教学特征以及课程评估方法。我们发现,大多数硬件安全课程并未将HRE作为优先事项,导致HRE培训资源稀缺。尽管讲座与动手项目相结合的普遍课程结构似乎在很大程度上是有效的,但我们观察到缺乏标准化的评估方法和学生自我评估调查的可靠性有限。我们的研究结果提出了对HRE教育可能的改进方案,并为开发新培训课程提供了建议。我们主张将HRE教育融入课程指南中,以满足日益增长的社会和工业对HRE专家的需求。
提供机构:
Center For Open Science



