PSA Certified

{{Other uses|PSA (disambiguation){{!}}PSA}}

{{Advert|date=March 2022}}

{{Infobox certification mark

| name = PSA Certified

| image = File:PSA_Certified.jpeg

| caption =

| image2 =

| caption2 =

| expansion =

| standards_org =

| agency =

| region = Worldwide

| founded = 2017

| defunct =

| predecessor =

| successor =

| products =

| type = Security certification scheme

| legalstatus =

| mandatorysince =

| homepage = [http://psacertified.org psacertified.org]

}}

Platform Security Architecture (PSA) Certified is a security certification scheme for Internet of Things (IoT) hardware, software and devices. It was created by Arm Holdings, Brightsight, CAICT, Prove & Run, Riscure, TrustCB and UL as part of a global partnership.

Arm Holdings first brought forward the PSA specifications in 2017 to outline common standards for IoT security{{cite web |last1=Dent |first1=Steve |title=Google and others back Internet of Things security push |url=https://www.engadget.com/2017-10-23-google-arm-internet-of-things-security.html |publisher=Engadget |date=October 23, 2017}} with PSA Certified assurance scheme launching two years later in 2019.

History

In 2017, Arm Holdings created Platform Security Architecture (PSA), a standard for IoT security. The standard builds trust between Internet of Things services and devices.{{cite web |last1=McGregor |first1=Jim |title=Not All Electronic Device Are Secure, But ARM's PSA May Change That |url=https://www.forbes.com/sites/tiriasresearch/2017/10/30/not-all-electronic-device-are-secure-but-arms-psa-may-change-that/#2f066dd3e0bb |work=Forbes |date=October 30, 2017}}{{cite web |last1=Takahshi |first1=Dean |title=Arm unveils security certification testing for IoT devices |url=https://venturebeat.com/2019/02/25/arm-unveils-security-certification-testing-for-iot-devices/ |publisher=VentureBeat}} It was built to include an array of specifications such as threat models, security analyses, hardware and firmware architecture specifications, and an open-source firmware reference implementation.{{cite web |title=Momentum Builds for PSA Certified |url=https://www.embedded-computing.com/guest-blogs/momentum-builds-for-psa-certified |publisher=Embedded Computing Design |date=March 30, 2020}} It aimed to become an industry-wide security component, with built-in security functions for both software and device manufacturers.

PSA has since evolved to become PSA Certified, a four-stage framework which can be used by IoT designers for security practices.{{cite web |last1=Khan |first1=Jeremy |title=SoftBank's ARM Makes Bid to Standardize IoT Security Industry |url=https://www.bloomberg.com/news/articles/2017-10-23/softbank-s-arm-makes-bid-to-standardize-iot-security-industry |publisher=Bloomberg |date=October 23, 2017}} The framework included different levels of trust, with each level contains a different level of assessment, with progressively increasing security assurances.{{cite web |last1=Condon |first1=Stephanie |title=Arm partners with testing labs to provide IOT security certification |url=https://www.zdnet.com/article/arm-partners-with-testing-labs-to-provide-iot-security-certification/ |publisher=ZDNet |date=February 25, 2019}}

In 2018, the first IoT threat models and PSA documents were published.{{cite web |last1=Williams |first1=Chris |title=Arm PSA IoT API? BRB... Toolbox of tech to secure net-connected kit opens up some more |url=https://www.theregister.co.uk/2018/10/17/arm_psa_iot/ |publisher=TheRegister |date=October 17, 2018}}

The certification of PSA Certified launched at Embedded World in 2019,{{cite web |last1=Hayes |first1=Caroline |title=Embedded World: Arm introduces fourth security element to PSA |url=https://www.electronicsweekly.com/market-sectors/internet-of-things/arm-introduces-fourth-security-element-psa-2019-02/ |publisher=Electronics Weekly |date=February 25, 2019}} where Level 1 Certification was presented to chip vendors. A draft of Level 2 protection was presented at the same time.{{cite web |title=PSA Certified–building trust, building value |url=https://www.eetimes.com/psa-certified-building-trust-building-value/ |publisher=EE Times |date=March 4, 2019}}

Six of the seven founding stakeholders created the PSA Certified specifications, which are now make up the PSA Joint Stakeholders Agreement. The stakeholders are Arm Holdings, Brightsight, CAICT, Prove & Run, Riscure and UL. TrustCB became the seventh PSA Certified JSA member, acting as an independent Certification Body for the scheme. Out of the six other founding members, four are security test laboratories, which includes Brightsight, CAICT, Riscure and UL.

The first PSA Certified Level 2 certificates were issued to chip vendors in February 2020.{{cite web |title=The $6trn importance of security standards and regulation in the IoT era |url=https://www.iot-now.com/2020/03/16/101805-6trn-importance-security-standards-regulation-iot-era/ |publisher=IoT Now |date=March 16, 2020}}

The first PSA Certified Level 3 certificate was issue in March 2021.{{Cite web|title=Secure Vault achieves PSA Certified Level 3 status|url=https://www.newelectronics.co.uk/electronics-news/secure-vault-achieves-psa-certified-level-3-status/235520/|access-date=2021-04-10|website=www.newelectronics.co.uk}}

Certification

The PSA Joint Stakeholders Agreement outlines how members can create a worldwide standard for IoT security that enables the electronic industry to have an easy to understand security scheme. The security certification scheme documents enable a security-by-design approach to a diverse set of IoT products. The scheme starts with a security assessment of the chip and its Root of Trust (RoT) and then builds outwards to the system software and device application code. PSA Certified specifications are implementation and architecture agnostic so can be applied to any chip, software or device.{{cite web |last1=McGregor |first1=Jim |title=Arm Introduces Security Certification Testing For IoT |url=https://www.forbes.com/sites/tiriasresearch/2019/03/04/arm-introduces-security-certification-testing-for-iot/#7c4aa91d38eb |work=Forbes |date=March 4, 2019}}

PSA Certified aims to removes industry fragmentation for IoT product manufacturers and developers in a number of ways. The world's leading IoT chip vendors are delivering system-on-chips built with a PSA Root of Trust (PSA-RoT) providing a new widely available security component with built-in security functions that software platforms and original device manufacturers (OEMs) can make use of.{{cite web |last1=Speed |first1=Richard |title=Azure IoT heads spacewards to maintain connectivity at the edge, courtesy of Inmarsat |url=https://www.theregister.co.uk/2019/02/25/azure_iot_takes_to_space/ |publisher=TheRegister |date=February 26, 2019}}

=Functional API certification=

A high-level set of APIs are provided by the PSA-RoT to abstract the trusted hardware and firmware used by different chip vendors. These APIs include:

  • PSA Cryptography API
  • PSA Attestation API
  • PSA Storage API

Open source API test suites are available to check compliance for PSA Functional API Certification. An open-source implementation of the PSA Root of Trust APIs is provided by the TrustedFirmware.org project.

=Level 1=

The first level of security certification for PSA Certified is Level 1, aimed at chip vendors, software platforms and device manufacturers. The certification consists of questions, document review and an interview by one of the certification labs. The completed answers are accompanied with explanatory notes, checked by the certification lab. According to the PSA Certified website, language and mappings align with other important IoT requirements, such as standards and laws. These include NISTIR 8259, ETSI 303 645 and SB-327.{{cite web |title=Level 1 |url=https://www.psacertified.org/security-certification/psa-certified-level-1/ |publisher=PSA Certified}}

=Level 2=

The mid-level security certification involves testing by a security lab, focusing on source code review and the PSA Root of Trust (PSA-RoT), over the course of a month to attain the level 2 certification. This process focuses on carefully defined attack methods and utilizes a set evaluation methodology.{{cite web |title=Arm Releases New Infrastructure and Security Certifications for IoT Devices |url=https://www.allaboutcircuits.com/news/arm-releases-new-infrastructure-security-certification-iot-devices/ |publisher=AllAboutCircuits |date=February 25, 2019}} It also ensures hardware must support PSA-RoT functions and is therefore aimed at chip vendors.

According to Forbes, they believed Level 2 was likely to become the most common level for consumer IoT applications.

=Level 3=

The final level extends the criteria of Level 2 to include protection against various physical attacks and side-channel attacks.

Industry adoption

Since the launch of the standard, it has been adopted by a number of chip manufacturers and system software providers.

class="wikitable sortable"
Company

! Certification Level

! Sector

! References

Aitos.io

| Level 1

| Blockchain

| {{cite web |title=aitos.io launches the world’s first PSA Certified BoAT blockchain application framework |url=https://aitos-io.medium.com/aitos-io-launches-the-worlds-first-psa-certified-boat-blockchain-application-framework-3a5b407983cf |publisher=Medium}}

Applus+

| Level 1

| Security lab

| {{cite web |title=Applus+ joins the PSA Certified scheme, as a security lab for IoT-device chips |url=https://www.appluslaboratories.com/global/en/news/applus+-joins-the-psa-certified-scheme,-as-a-security-lab-for-iot-device-chips- |publisher=Applus}}

Crypto Quantique

| Level 2

| OEM

| {{cite web |title=Securing the IoT ecosystem |url=https://www.newelectronics.co.uk/electronics-technology/securing-the-iot-ecosystem/240885/ |publisher=New Electronics |date=September 30, 2021}}

Cypress Semiconductor

| Level 2

| Chip manufacturer

| {{cite web |url=https://www.businesswire.com/news/home/20190226005439/en/Cypress-Processing-Solution-Built-in-System-Layer-Security | title=Cypress Processing Solution with Built-in System Layer Security Fortifies IoT Application Design

}}

ECSEC Laboratory

| Level 1

| Security lab

| {{cite web |title=PSA Certification |url=https://www.ecsec.jp/publics/index/33/ |publisher=ECSEC}}

Embedded Planet

| Level 2

| OEM

| {{cite web |title=Arrow Electronics Accelerates Development of IoT Devices on PSA Certified Trusted Methodology |url=https://www.eetasia.com/arrow-electronics-accelerates-development-of-iot-devices-on-psa-certified-trusted-methodology/ |publisher=EE Times}}

Eurotech

| Level 1

| OEM

| {{cite web |title=Eurotech achieves IoT security certification |url=https://www.eurotech.com/en/news/psa-certified-level-1-iot-security |publisher=Eurotech |date=July 7, 2021}}

Express Logic

| Level 1

| Software platform

| {{cite web |title=Express Logic's X-Ware IoT Platform is now Arm PSA Certified |url=https://www.embedded-computing.com/iot/express-logic-s-x-ware-iot-platform-is-now-arm-psa-certified |publisher=Embedded Computing}}

FreeRTOS

| Level 1

| Software platform

| {{Cite web|date=2020-03-16|title=FreeRTOS {{!}} PSA Certified|url=https://www.psacertified.org/products/freertos/|access-date=2021-04-09|language=en-GB}}

Infineon

| Level 2

| Chip manufacturer

| {{cite web |title=PSoC 64 Standard Secure MCU family achieves PSA Level 2 certification |url=https://www.newelectronics.co.uk/electronics-news/psoc-64-standard-secure-mcu-family-achieves-psa-level-2-certification/240427/ |publisher=New Electronics |date=September 21, 2021}}

InGeek

| Level 1

| OEM

| {{cite web |title=InGeek Embedded World PSA Certified |url=https://www.ingeek.com/blog/embedded-world-psa |publisher=InGeek}}

Macronix

| Level 1

| OEM

| {{cite web |title=Macronix ArmorFlash NOR Flash achieves PSA Certified Level 1 status |url=https://www.newelectronics.co.uk/electronics-news/macronix-armorflash-nor-flash-achieves-psa-certified-level-1-status/239964/ |publisher=New Electronics |date=August 31, 2021}}

Microchip Technology

| Level 1

| Chip manufacturer

| {{cite web |title=SAM L10 and SAM L11 Microcontroller Family |url=https://www.microchip.com/design-centers/32-bit/sam-32-bit-mcus/sam-l-mcus/sam-l10-and-l11-microcontroller-family |publisher=Microchip Technology}}

Nordic Semiconductor

| Level 1

| Chip manufacturer

| {{cite web |title=Nordic nRF9160 SiP among first of major semiconductor vendor products to gain PSA Certification for IoT trusted security |url=https://www.nordicsemi.com/News/2019/02/nRF9160-SiP-gains-Arm-PSA-Certified-Level-1-certification-for-IoT-trusted-security |publisher=Nordic Semiconductor}}

Nuvoton

| Level 1

| Chip manufacturer

| {{cite web |title=Nuvoton Debuts PSA Certified Level 1 and PSA Functional API Certified Arm Cortex-M23 Based MCU for Global Market Targeting IoT Security |url=https://www.nuvoton.com/news/news/products-technology/TSNuvotonNews-000247/ |publisher=Nuvoton}}

NXM Labs

| Level 1

| Software platform

| {{cite web |title=NXM Achieves PSA Level One Certification from UL for its Autonomous Security Software |url=https://www.ul.com/news/nxm-achieves-psa-level-one-certification-ul-its-autonomous-security-software |publisher=UL |date=October 8, 2019}}

NXP Semiconductor

| Level 2

| Chip manufacturer

| {{cite web |last1=Dordyk |first1=Susan |title=MCU leverages IoT security assurance |url=https://www.edn.com/mcu-leverages-iot-security-assurance/ |publisher=EDN}}

OneOS

| Level 1

| Software platform

| {{cite web |title=OneOS certification |url=https://www.psacertified.org/products/oneos/ |publisher=PSA Certified}}

Renesas Electronics

| Level 2

| Chip manufacturer

| {{cite web |title=Renesas Electronics Unveils RA Family of 32-Bit Arm Cortex-M Microcontrollers with Superior Performance and Advanced Security for Intelligent IoT Applications |url=https://www.renesas.com/us/en/about/press-center/news/2019/news20191008.html |publisher=Renesas}}

RT-Thread

| Level 1

| Software platform

| {{cite web |last1=Cohen |first1=Perry |title=RT-Thread IoT OS Achieves PSA Security Certification |url=https://www.embedded-computing.com/iot/rt-thread-iot-os-achieves-psa-security-certification |publisher=Embedded Computing Design}}

Sequitur Labs

| Level 1

| Software platform

| {{cite web |title=Sequitur Labs’ EmSPARK 2.0 Security Suite achieves PSA Certified status |url=https://www.newelectronics.co.uk/content/news/sequitur-labs-emspark-2-0-security-suite-achieves-psa-certified-status |publisher=New Electronics}}

Silicon Labs

| Level 3

| Chip manufacturer

| {{cite web |last1=Dahad |first1=Nitin |title=Silicon Labs First to Achieve PSA Certified Level 3 Status for Wireless SoC |url=https://www.eetasia.com/silicon-labs-first-to-achieve-psa-certified-level-3-status-for-wireless-soc/ |publisher=EE Times |date=March 17, 2021}}

Shenzhen Goodix

| Level 1

| Chip manufacturer

| {{cite web |title=Goodix receives PSA Certification |url=https://www.eet-china.com/info/202109261014.html |publisher=EE Times China |language=Chinese}}

STMicroelectronics

| Level 3

| Chip manufacturer

| {{cite web |title=Dev kits and software for STM32U5 – and chips now available |url=https://www.electronicsweekly.com/news/design/dev-kits-software-stm32u5-chips-now-available-2021-10/ |publisher=Electronics Weekly |date=October 1, 2021}}

Unisoc

| Level 1

| Chip manufacturer

| {{cite web |title=Unisoc Launches All-New AIOT Solution V5663 |url=http://www.unisoc.com/unparalleled-unisoc-launches-all-new-aiot-solution-v5663 |publisher=Unisoc |date=March 2, 2020}}

Veridify

| Level 1

| Software platform

| {{cite web |title=Veridify Security's DOME Client Library Achieves PSA Certified Level 1 Accreditation |url=https://www.embeddedcomputing.com/technology/security/software-security/veridify-security-s-dome-client-library-achieves-psa-certified-level-1-accreditation |publisher=Embedded Computing (magazine)}}

Winbond

| Level 2

| Chip manufacturer

| {{cite web |title=Winbond TrustME Secure Flash Memory achieves PSA Certified Level 2 |url=https://www.winbond.com/hq/about-winbond/news-and-events/news/news00511.html?__locale=en |publisher=Winbond |date=February 26, 2020}}{{cite web |last1=Winning |first1=Ally |title=Winbond TrustME secure flash gets PSA Certified Level 2 Ready |url=https://www.eenewsembedded.com/news/winbond-trustme-secure-flash-gets-psa-certified-level-2-ready |publisher=EE News}}

Zephyr OS

| Level 1

| Software platform

| {{cite web |title=Linaro contributes to the Zephyr Project becoming PSA certified |url=https://www.linaro.org/news/linaro-contributes-to-the-zephyr-project-becoming-psa-certified/ |publisher=Linaro}}

References