Meaning
Security evaluation standards define standardized methodology profiles for assessing connected platform hardware and platform software security guarantees. Reaching SESIP Level 3 proves that an internet-of-things platform component incorporates hardware-backed resistance against moderate-attack-potential physical and software threats. The methodology aligns evaluation requirements with Common Criteria methodology tailored specifically for smart devices.
The scope covers the hardware root of trust and platform security services.
Target Security
Platform architectures implement isolated execution environments to protect cryptographic management functions. Software components operating in unprivileged domains access cryptographic services through defined application programming interfaces. Cryptographic engines protect stored credentials against unauthorized read operations.
Isolation prevents privilege escalation.
Vulnerability Testing
Evaluators conduct focused source code analysis and physical fault injection testing on sample devices. Laboratories subject candidate hardware to clock manipulation, voltage glitching, and software fuzzing attacks to identify potential security bypasses. Security flaws require remediation before final certification sign-off.
Testers verify patch effectiveness.
Compliance Verification
Certification bodies review laboratory evaluation reports against standardized protection profiles to verify implementation compliance. Documentation checks confirm that secure lifecycle management, key storage mechanisms, and update mechanisms meet specification requirements. Passing SESIP Level 3 validation allows module vendors to demonstrate security compliance across global commercial markets.