The IoT is expected to comprise 20.8 billion devices by 2020, with Gartner estimating that 5.5 million new ‘things’ went online daily during 2016. Nevertheless, robust IoT security remains mired in the creation phase along with nascent interoperability standards. As more and more ‘things’ connect to the Internet, the danger of nefarious attackers exploiting unsecured devices looms ever larger.
Security IP
Token Gateway
As the mobile payments ecosystem matures, connections need to be established with the payments schemes and OEM Pay wallets, and the security behind mobile payments needs to be implemented.
Smarter than a Smart Card
Set-top boxes (STBs) were initially secured by Conditional Access System (CAS) smart cards. However, this approach is no longer effective. Smart cards cannot prevent unauthorized access to premium 4K and UHD content, as they are not designed to protect the interface between the card and box, or the STB SoC itself. This is one of the reasons why cardless CAS set-top boxes, equipped with a hardware-based root-of-trust, are increasing in popularity amongst major operators such as Dish TV India. A hardware root-of-trust, provided by platforms such as Rambus’ CryptoMedia, offers operators robust security protection with an integrated security core that acts to effectively decrease potential attack vectors. Moreover, eliminating the smart card significantly reduces cost, for both short-term BOM and long-term liability in the form of frequent card swaps. It should be noted that not all hardware security cores are created equal. One important consideration is that any hardware security core should be compatible with multiple leading CAS and DRM systems. This ensures operators are not locked into a single vendor for the entire lifetime of a set-top box. Moreover, the ability to function alongside numerous CAS and DRM systems can potentially enable new ways of securely distributing pay content, offering tangible benefits to both DTH operators and OTT distributors. For example, operators can provide their subscribers OTT content alongside broadcast content on the same set-top box, using the same robust hardware security, while maintaining cryptographic isolation between the different systems.
CryptoMedia Security Platform Solution Overview
Use Cases: Personalization
Related to the inherent complexities and costs associated with building a brand new chip, fabless chip manufacturers are under constant pressure to improve operating efficiencies while, at the same time, satisfying OEM customer requirements. As such, large OEM customers requesting personalization, customer specific data preparation and feature customization of standard parts challenge the chipmakers ability to minimize inventory overhead and improve operating efficiencies.
Customer specific personalization services may be accomplished with a high degree of visibility and audit tracking controls that are secured by the CryptoManager solution for each step in the manufacturing supply chain.
For example (see Figure 1), if three OEM customers of a SoC manufacturer each request different feature configurations and/or data preparations for a standard SoC product, the SoC manufacturer needs to figure out how to support three customerspecific part types without creating three different SKUs.
Device personalization creates complexity in manufacturing and in inventory management. With multiple SKUs for standard products, managing inventory for each step requires accurate forecasts and discrepancies can result in wasted silicon or delays in fulfilling orders (see Figure 2)
In this case, pushing the personalization processing step to the end of the manufacturing flow just prior to or, in some cases after delivery to the customer, mitigates the impact on inventory and operations (See 3).
Use Cases: Secure Key Provisioning
With mobile devices housing more and more sensitive data that is utilized in a wide variety of applications, chip and device companies must meet the complex security requirements for each potential use case or capability. Most security measures require the injection of secret identity data and cryptographic keys. Currently, cryptographic keys are provisioned in the open without encryption on test equipment which is operated by third party contract manufacturers. These current provisioning methods expose chip manufacturers to liability and risks for any security breach that occurs within their supply chain.
Utilizing the CryptoManager Root of Trust hardware IP Core, SoC architects have a built-in design for the secure provisioning of cryptographic keys during chip manufacturing. For OEM device manufacturing, this feature also enables remote secure key provisioning at the ODM (Original Device Manufacturer).
