Internet of Things (IoT) smart devices numbering in the billions and connected via the internet are increasingly vital to society and the global economy. However, the very “connectedness” that makes IoT devices so valuable can be turned to an enormous liability if these devices are left unprotected from security-related threats. This paper explores the threat environment faced by, and the concepts and methods for securing, IoT devices.
Search Results for: IoT security
Rambus Joins DARPA Toolbox Initiative with State-of-the-Art Security and Interface IP
Highlights:
- Agreement makes Rambus Root of Trust, Secure Protocol Engines, along with Memory and SerDes PHYs and Controllers available to DARPA researchers
- Streamlined access to cutting-edge silicon IP accelerates forward-looking innovation
- DARPA researchers will be able to leverage industry-leading capabilities and expertise from Rambus
SAN JOSE, Calif. – April 14, 2021 – Rambus Inc. (NASDAQ: RMBS), a provider of industry-leading chips and silicon IP making data faster and safer, today announced a commercial licensing agreement with the U.S. Defense Advanced Research Projects Agency (DARPA) to accelerate technology innovation for the agency’s programs. The agreement makes all Rambus security, memory interface, and SerDes interface IP products available to DARPA researchers. As licensees, DARPA researchers benefit by having access to IP offering renowned security protection and the world’s fastest chip interfaces.
“Rambus has the industry’s broadest portfolio of state-of-the-art security IP products, and offers leading interface IP at some of the highest bandwidths available,” said Sean Fan, chief operating officer at Rambus. “We are excited to add our full suite of cutting-edge silicon IP to DARPA Toolbox, and look forward to the new opportunities to provide our solutions and expertise for their ecosystem.”
The DARPA Toolbox initiative is an agency-wide effort to provide open licensing opportunities with commercial technology vendors to the researchers behind DARPA programs. Through DARPA Toolbox, successful proposers will receive greater access to commercial vendors’ technologies and tools via pre-negotiated, low-cost, non-production access frameworks and simplified legal terms. For commercial vendors, DARPA Toolbox will provide an opportunity to leverage the agency’s forward-looking research and a chance to develop new revenue streams based on programmatic achievements developed with their technologies.
“With Rambus joining our DARPA Toolbox Initiative, we add state-of-the-art security and interface technologies,” Serge Leef, the Microsystems Technology Office (MTO) program manager at DARPA leading DARPA Toolbox. “Our researchers will now have streamlined access to this cutting-edge IP to accelerate the speed of development for their projects.”
Through the DARPA Toolbox, researchers will have access to all Rambus Security, Memory Interface and SerDes Interface IP solutions including:
Rambus Security IP
- Root of Trust Solutions
- Secure Protocol Engines for MACsec, IPsec and TLS/DTLS/SSL
- Cryptographic Accelerator Cores
Rambus Memory and SerDes Interface IP
- HBM2E Memory Interface (PHY and controller)
- GDDR6 Memory Interface (PHY and controller)
- PCI Express 5.0 Interface (PHY and controller)
Rambus is one of a limited number of select technology companies to sign commercial partnership agreements under DARPA Toolbox. Rambus technologies under the initiative serve a broad range of applications from Data Center, Edge, 5G networking, Artificial Intelligence (AI), to Internet of Things (IoT).
For more information on Rambus Security solutions, please visit rambus.com/security. To learn more about Rambus Interface IP, visit rambus.com/interface-ip/.
Consumer Privacy and Safety at Risk from Unprotected IoT Devices
Rambus’ Paul Karazuba recently penned an article for Semiconductor Engineering that takes a closer look at how consumer privacy and safety continue to be at risk from unprotected IoT devices. As Karazuba notes, security cameras represent approximately 47 percent of vulnerable devices installed on home networks. Basic attack techniques that target these devices, says Karazuba, include a simple process known as credential stuffing, with attackers accessing accounts using stolen credentials and large-scale automated login requests.
“Camera users who don’t enable the optional two-step authentication, skip setting a unique password, or recycle credentials across multiple online services and are at a greater risk of being hacked,” he explains.
Beyond security cameras, emphasizes Karazuba, a wide range of vulnerable consumer IoT devices are frequently targeted by hackers who actively search for devices with default or weak login credentials such as ‘admin’ usernames and ‘1234’ passwords. These include network-attached storage devices, printers, smart TVs, and IP phones.
Fortunately, says Karazuba, states like California and Oregon are proactively formulating legislation that could help prevent basic attacks against unprotected and vulnerable IoT devices. Indeed, California cybersecurity law SB-327, which went into effect on January 01, 2020, requires manufacturers to equip IoT devices with reasonable security features to prevent unauthorized access, modifications, and data leaks.
Specifically, SB-327 requires manufacturers to implement a unique preprogrammed (default) password for each device. Additionally, manufacturers must ensure that users create a new password the first time a device is activated. Together, explains Karazuba, these steps are expected to help protect California consumers, as hackers are known to routinely target vulnerable devices shipped with generic or default login credentials.
Another example of proactive legislation is Oregon House Bill 2395 which requires manufacturers to equip IoT devices with “reasonable security features.” These include shipping devices with unique preprogrammed passwords, requiring users to create new passwords when a device is first activated, and ensuring manufacturers comply with federal law and regulations that apply to security measures for connected devices.
As Karazuba points out, additional governments around the world are beginning to recognize the real-world risks posed by unprotected IoT devices.
“For example, the United Kingdom (UK) recently announced its intention to introduce new laws requiring security to be built into IoT devices,” he writes. “This would add to the UK government’s 2018 publication of the world’s first IoT code of practice, which outlines guidelines for manufacturers such as prohibiting default passwords and mandating secure credential storage as well as ensuring software integrity.”
According to Karazuba, passing proactive security legislation to prevent basic attacks against unprotected and vulnerable IoT devices is a good first step to protecting consumer privacy and safety. However, there is clearly much more that needs to be done before connected devices are secured against more sophisticated attacks.
“A siloed security co-processor, designed to execute security-centric processes completely independently of the main CPU, can better help protect consumers by preventing unauthorized access and monitoring suspicious system activity,” he elaborates.
Specifically, says Karazuba, a security co-processor can enable secure boot and runtime integrity checking, as well as provide remote authentication and attestation and hardware acceleration for symmetric and asymmetric cryptographic algorithms.
“Put simply, a siloed security co-processor can help thwart determined adversaries and more sophisticated hacking techniques such as side-channel attacks,” he concludes.
Security is Critical at the Intersection of AI and 5G
Rambus’ Tim Messegee has penned an article for Semiconductor Engineering that takes an in-depth look at the importance of ensuring security at the intersection of AI and 5G. As Messegee notes, 5G represents nothing less than a revolution in mobile technology with performance that is poised to rival that of wireline networks.
“Relative to its 4G predecessor, 5G promises 10X the data rate, 100X the efficiency, and 1000X the capacity, at 1/100th the latency,” he elaborates. “With 1Gbps speed at 1ms latency, 5G makes it possible to offer a host of real-time applications and services.”
Real-time is critical, says Messegee, because the rise of artificial intelligence (AI) runs in parallel to the roll out of 5G.
“As AI increasingly moves into controlling devices in the physical world, from delivery drones to autonomous vehicles, the high-speed, Ultra-reliable Low Latency Communication (uRLLC) links that 5G provides become a critical enabler,” he explains. “Most of 5G’s ‘users’ will be the things of the Internet of Things (IoT). Human users will benefit both from the improved high-data rate mobile experience of 5G, and from the AI-enabled and 5G-connected devices that will make our world smarter, safer, and more convenient.”
The vast number of 5G-connected IoT devices, Messegee notes, will generate a torrent of data.
“In a true virtuous cycle, 5G networks will make possible the collection of this enormous quantity of data,” he adds. “AI training requires vast amounts of data, and AI will be the only practical means of managing all this data.”
In this way, says Messegee, the success of 5G and AI are inextricably tied. While independently they create enormous value, together they create exponentially more. And with significantly increasing value, the imperative to protect said value rises commensurately.
“By their very nature, 5G networks will have increased attack surface that adversaries will try to exploit. For instance, to meet its [low] latency targets, 5G architecture pushes more computing to the edge of the network,” he writes. “For AI, this will enable both inference and even training at the edge. This distributes valuable AI algorithms (more opportunities for attack) and takes them out of the hardened data center environment (a lower barrier for attack).”
According to Messegee, this is precisely why it is so critical to safeguard the data carried by 5G networks. For example, with AI-powered devices flying the skies, driving the roads, and protecting neighborhoods, an attack which compromises the data coursing to and from these devices can threaten privacy, property, and personal safety.
“Thirty years of the web have made it abundantly clear that software-level security alone is not up to the task of protecting the real-time, always-on world of 5G and AI,” he explains. “The whack-a-mole game of patching software vulnerabilities is far too risky given the stakes. Protecting 5G networks, and the AI-enabled IoT devices that depend on them, will require security anchored in hardware.”
More specifically, says Messegee, secure processing cores embedded in the chips at the heart of 5G and AI devices can enable a system-level security architecture that can protect the entire network.
“Provisioned at time of manufacture, these trusted devices can attest to the validity of electronic systems and the data they process and communicate,” he states. “Hardened against direct and side-channel attacks, they extend protection to the edge and to end-point devices. Intelligent and flexible, they can be managed in the field to adapt to an evolving threat landscape.”
As Messegee emphasizes, there are incredible synergies to be realized when 5G meets AI.
“It is imperative that security anchored in hardware is part of the fundamental design philosophy of 5G and AI systems given the great value at issue,” he concludes.
Rambus and the OCP: Tackling Cloud Data Security with a Hardware Root of Trust
Founded in 2009, the Open Compute Project (OCP) is a collaborative community focused on redesigning hardware technology to efficiently support the growing demands on compute infrastructure. More recently, the OCP formed a security working group to tackle the formidable challenges of data security in the cloud, including the increasing sophistication of malicious actors. In conjunction with their tech week, today the OCP announced the version 1.0 Root of Trust (RoT) specification.
The OCP specification starts with the requirement that both the platform (the server being protected) and device must have a hardware RoT. Amongst its many responsibilities, the RoT verifying the device firmware at boot, maintains authenticity during updates, and recovers in the event of corruption. The OCP specification further specifies how a system should boot: each device/peripheral must first boot securely, using the RoT to ensure authenticity of its firmware. It must verify the firmware’s cryptographic signatures using a policy that is defined by the system owner for authorizing only valid firmware signers. Then, the platform RoT is responsible for requiring all devices in the system to attest – to prove in an irrefutable way that the firmware it is running is indeed what is expected. Once the platform RoT has booted the platform successfully, and has attested all devices, the platform is finally considered to be secured. Of note, the first release includes specifications for secure boot, peripheral attestation, and threat scope.
Rambus is pleased to announce our support for this specification, as we have long touted that a hardware root of trust is and must be the foundation of any secure system. OCP’s method of mandating a hardware RoT on every device is a prudent one – each and every device within a system must be secure, and be able to be trusted by every other device in that system. Without a root of trust, this is not possible. Rambus offers a broad portfolio of robust root of trust solutions, ranging from richly featured defense-grade co-processors to highly compact state machines suitable for IoT devices. These solutions provide robust security capabilities including unique identification, security lifecycle management, attestation, secure boot, secure update, anti-rollback, isolation, interaction, secure storage, and cryptographic/trusted services. With a breadth of solutions applicable from the data center to endpoint devices, Rambus has a root of trust solution for almost every application.
During the OCP tech week, there are a number of security-specific sessions Thursday, November 12 and Friday, November 13th. More information on these is available at https://www.opencompute.org/summit/ocp-tech-week


