RDK continuously puts efforts to identify and prevent/mitigate several threats including unauthorized distribution, fraudulent access, and data tampering including re-direction to illicit content and Denial Of Service (DOS) attacks in the RDK based CPE. With Wi-Fi, Ethernet, MoCA, Bluetooth, and other points of ingress to the network available on all CPE, and accessible to any device with the same kind of port, a myriad of additional threats are potentially exposed. Therefore, controlling access to valuable service content, network infrastructure, personal information, Internet traffic, neighboring systems, and a multitude of in-home devices, is critical to everyone’s success throughout RDK Operators. As a result, a suite of specifications and recommendations is provided, covering broad security features such as content protection, digital rights management, software security, and more.
There are many security features in the RDK, and the three major features in the platform are - Containerization, Access Control, and Kernel Hardening.
Note: The aforementioned security features are by default present in RDK Video releases but are not the part of default configuration in RDK Broadband releases.
This wiki space is used to document RDK security features taken up by Comcast - RDK Management team. Has 3 sub-sections: Security feature releases to RDK Community. Will have: 1 - Security Requirement Specification for the feature (currently under review) 2 - Reference Implementation in any reference platform - RPI or Video Accelerators 3 - Certification Suite to validate the feature requirements (currently under planning) Restricted to RDKM and development community. Will have analysis, development and POC details conducted on each security feature. Restricted to RDKM security core team to keep any confidential information. |