Skip to main navigation Skip to search Skip to main content

Consumer electronics supply chain poisoning: anatomizing the unified hardware and software threat model and countermeasures

Research output: Contribution to journalReview articlepeer-review

Abstract

With attackers increasingly targeting consumer electronic devices, the urgency of strengthening supply chain security has never been more pressing. To address this critical issue, we present a Unified Hardware and Software Threat Model (UHSTM) for consumer devices’ supply chains that classifies threats and describes attack surfaces in a unified way, ensuring that security recommendations are implemented across the entire consumer device lifecycle, from design and production to distribution and operation, considering hardware and software attack surfaces. UHSTM holistically and proactively addresses the interconnected and complex security risks that arise from integrating diverse hardware components and software systems. We discuss the UHSTM implementation and present robust countermeasures that enable field practitioners to circumvent risks proactively by enhancing electronic devices’ hardware and software security posture.

Original languageEnglish
Pages (from-to)251-260
Number of pages10
JournalInformation Security Journal
Volume35
Issue number2
DOIs
StatePublished - 2026

Bibliographical note

Publisher Copyright:
© 2025 Taylor & Francis Group, LLC.

Funding

Sherali Zeadally was partially supported by a Distinguished Visiting Professorship award from the University of Johannesburg. We thank the anonymous reviewers for their valuable comments which helped us improve the content, organization, and presentation of this paper.

Funders
University of Johannesburg

    Keywords

    • Consumer device security
    • cyberattacks
    • hardware security
    • software security
    • supply chain security

    ASJC Scopus subject areas

    • Software
    • Computer Science Applications
    • Information Systems and Management

    Fingerprint

    Dive into the research topics of 'Consumer electronics supply chain poisoning: anatomizing the unified hardware and software threat model and countermeasures'. Together they form a unique fingerprint.

    Cite this