The IoT is expected to comprise 20.8 billion devices by 2020, with Gartner estimating that 5.5 million new ‘things’ went online daily during 2016. Nevertheless, robust IoT security remains mired in the creation phase along with nascent interoperability standards. As more and more ‘things’ connect to the Internet, the danger of nefarious attackers exploiting unsecured devices looms ever larger.
Search Results for: IoT security
Rambus talks vehicle security at TU-Automotive
Joe Gullo, the senior director for Rambus automotive strategy and development, recently participated in a TU-Automotive panel that explored the importance of securing next-gen autonomous vehicles. Indeed, the number of threat vectors in the automotive sector have exponentially increased in recent years. This is due to a range of factors, such as more complex software code, ubiquitous connectivity, a greater number of components and broader functionality.
Gullo kicked off his Q&A session by observing that automotive security best practices currently fall into three primary categories: authentication, multi-faceted designs, and flexibility.

“Authentication needs to happen in both directions. In other words, the car has to trust the cloud and the cloud has to trust the car,” he told panel participants and conference attendees. “Unfortunately, I think that authenticating vehicles sometimes gets less attention than it should. This is also true for any IoT device, even refrigerators and washing machines.”
As Gullo pointed out, a multi-faceted design approach is required to address a range of threat vectors, including attacks on the cloud-to-car connection, the in-vehicle network and specific ECUs. However, he emphasized there isn’t a “single, simple solution” that offers optimal security.
“For example, the components for V2X security may not be effective for monitoring and protecting in-vehicle networks. In general, security architectures need to be flexible because future threats are unlikely to resemble our current understanding of threat vectors,” Gullo explained. “These architectures need to have the ability to learn, evolve, and improve ‘in the field’ as new threats emerge. We also need to be thoughtful regarding solution complexity so systems can be adapted quickly as new threats emerge. This means relying on the fundamentals, such as proven algorithms, robust key management, secure boot loaders and constant threat detection, for example.”
As Gullo noted, this is precisely why automotive security architecture needs to evolve from static, simple solutions to a more dynamic framework that is self-learning, easily updatable and multi-faceted to address multiple threat vectors. This progression inevitably brings a number of new issues to the fore, including end-to-end secure data storage for autonomous vehicles.
“There are a host of companies whose core competence is secure, cloud-based data storage. OEMs can and should leverage these companies, although they should make it clear that while partners are tasked with securely storing data, they don’t own it,” Gullo opined. “Analyzing the data, generating insights from the information and acting on those insights is solely within the purview of the OEMs. Also, it goes without saying that a robust key management solution is required to secure the data in the vehicle and during transmission to and from the cloud service.”
To be sure, there are expected to be more than 350 million connected cars on the road by 2020. Google’s autonomous vehicles generate about 1 gigabyte of data every second, while Intel says autonomous vehicle are likely to produce about 2 petabytes of data per year. Information generated by connected and autonomous vehicles includes environmental data, as well as vehicle and driver performance.
“Maintaining the integrity of safety-critical and forensic vehicle data, particularly with respect to V2X, driver performance and vehicle performance, is absolutely critical. While some data should be shared for the ‘common good,’ it will undoubtedly be challenging to reach consensus on precise parameters,” Gullo emphasized. “Whether it’s through the Auto-ISAC or some other consortium, the industry clearly needs to agree on a ‘common good’ data set and ensure that vehicle owners are aware of the requirement to share this information.”
Gullo also described current security standards, specifications and guidelines including the ISO 26262 standard for functional safety and SAE’s J3061 Cybersecurity Guidebook (for Cyber-Physical Vehicle Systems).
“There is also SAE’s pending J3101 standard titled Requirements for Hardware-Protected Security for Ground Vehicle Applications, while UMTRI and the Southwest Research Institute are working on a framework for secure OTA software and firmware upgrades. This space is still evolving, although quite a lot has already been accomplished,” he added.
Mirai botnet targets IoT devices
In late September, cybersecurity journalist Brian Krebs’ website was overwhelmed by a massive DDoS attack that hit at a rate of 620Gbps, forcing Akamai to temporarily suspend service. In a blog post describing the cyber assault, Krebs said the attack had likely been conducted with the help of a botnet that enslaved a significant number of compromised IoT devices, including routers, IP cameras and digital video recorders (DVRs).

Subsequently, Krebs confirmed that the source code powering the IoT botnet responsible for the attack had been publicly released. According to the journalist, the easy availability of the code “virtually guarantees” that the Internet will soon be flooded with attacks from many new botnets powered by insecure routers, IP cameras, digital video recorders and other easily hackable devices.
“The malware, dubbed ‘Mirai,’ spreads to vulnerable devices by continuously scanning the Internet for IoT systems protected by factory default or hard-coded usernames and passwords,” Krebs explained. “Vulnerable devices are then seeded with malicious software that turns them into ‘bots,’ forcing them to report to a central control server that can be used as a staging ground for launching powerful DDoS attacks designed to knock Web sites offline.”
Perhaps more disturbingly, Mirai is reportedly only one of at least two malware families that are currently being used to assemble large IoT-based armies.
“The other dominant strain of IoT malware, dubbed ‘Bashlight,’ functions similarly to Mirai in that it also infects systems via default usernames and passwords on IoT devices,” Krebs stated. “According to research from security firm Level3 Communications, the Bashlight botnet currently is responsible for enslaving nearly a million IoT devices and is in direct competition with botnets based on Mirai.”
Commenting on the recent slew of DDoS attacks, Asaf Ashkenazi, a senior director of product management at Rambus’s security division, notes that it is important for consumers to be aware of the very real threat posed by insecure IoT devices, including connected appliances, routers, IP cameras and digital video recorders. Indeed, unlike PCs and mobile devices such as tablets or smartphones, serious or even critical vulnerabilities are very rarely addressed with firmware updates by manufacturers in a timely manner, if at all.
“As more and more devices go online, the specter of nefarious attackers maliciously exploiting hapless victims looms ever larger. Of course, the overall effectiveness of a DDoS attack ultimately depends on the amount of IoT devices participating in any given DDoS campaign,” Ashkenazi wrote in an October 2016 Semiconductor Engineering article. “Vulnerable IoT endpoints clearly provide attackers with the scalability needed to launch effective DDoS attacks.”
In addition, says Ashkenazi, a new approach, designed from the ground up to provide security for connected devices, is obviously long overdue. One approach to achieving a safer IoT would see devices secured throughout their lifecycle from chip manufacture, to day-to-day deployment, to decommissioning. This can be accomplished with a silicon-based hardware root-of-trust that offers a range of robust security options for IoT devices, including secure connectivity between the IoT device and its cloud service.
“It may also be time to seriously re-examine the current state of DDoS protection on the service side. One possible way of shoring up defenses against costly DDoS attacks would be to bolster cloud service security,” he added. “This can be done by uniquely and cryptographically verifying each IoT device to determine if it is authorized to connect to a particular service. Devices that are not authenticated can be denied access to the service, which would, in turn, reduce the effectiveness (and damage) of a DDoS attack.”
Mirai botnet targets IoT devices
In late September, cybersecurity journalist Brian Krebs’ website was overwhelmed by a massive DDoS attack that hit at a rate of 620Gbps, forcing Akamai to temporarily suspend service. In a blog post describing the cyber assault, Krebs said the attack had likely been conducted with the help of a botnet that enslaved a significant number of compromised IoT devices, including routers, IP cameras and digital video recorders (DVRs).
Taking smartphone security to the next level
Asaf Ashkenazi, a senior director at Rambus’ security division, recently gave a keynote presentation about the future of mobile security at the Linley Group’s Mobile and Wearables Conference.
According to Ashkenzai, the demand for trusted applications on mobile devices has increased significantly in recent years.
“As the amount of valuable data stored and communicated across mobile devices continues to grow, the need for robust security solution becomes even more important,” he told conference participants.

“For example, there is a critical need for a security platform capable of addressing the distribution and authentication of cryptographic keys throughout the lifecycle of a device. From chip management to device personalization to downstream feature provisioning, it is important to create a trusted path from the SoC manufacturing supply chain to downstream service providers with a complete silicon-to-cloud solution.”
As Ashkenazi notes, this is precisely why Rambus’ CryptoManager platform establishes a hardware-based root-of-trust by embedding a security core in the SoC itself. This allows vendors to securely provision unique keys for each chip during the silicon manufacturing and testing process.
“With CryptoManager, an OEM building a device with an SoC from a chipset vendor does not need to provision keys or take any extra steps to enable security features,” he explained. “Service providers can also securely and conveniently provision keys over the air. Moreover, CryptoManager can be deployed across a wide range of key verticals, including mobile digital rights management, mobile payments and smart ticketing.”

In addition to its flagship hardware core, says Ashkenazi, the CryptoManager platform offers customers multiple implementation options, such as an integrated Software Agent and Trusted Execution Environment (TEE), as well as a stand-alone Software Agent. The former is implemented via software as a protected element within a trusted OS to deliver a combination of security and flexibility. Similarly, the latter is implemented in the software layer of a device OS to facilitate a high level of flexibility.
“Put simply, CryptoManager offers our customers and partners far more than key provisioning capabilities,” he added. “We support enhanced security for applications and data, alongside full device lifecycle management.”
Indeed, as we’ve previously discussed on Rambus Press, CryptoManager is a complete silicon-to-cloud solution for the distribution and authentication of cryptographic keys throughout the lifecycle of a device. The platform enables dynamic SoC management and device personalization in the supply chain, securing applications and services via in-field key provisioning.
CryptoManager includes a Security Engine, which is a flexible root-of-trust implemented as hardware or software, for secure provisioning, configuration, keying and authentication throughout the lifecycle of a device. A local and cloud-based CryptoManager Infrastructure and Trusted Provisioning Services support the Security Engine, providing chipmakers, device OEMs, secure application developers and service providers a scalable and flexible trust management solution.
By offering a secure foundation for downstream device configuration, chipmakers are granted the flexibility needed for post-manufacturing inventory management, while service providers have a trusted path to consumers for feature enablement and service delivery in applications including secure mobile banking, identity and entertainment, as well as IoT device security.
Interested in learning more? You can check out our official CryptoManager product page here.
Redesigning smart sensors for the IoT
Ed Sperling of Semiconductor Engineering observes that sensor technology is beginning to change on a fundamental level. Indeed, companies are now looking beyond the five senses – on which early sensors were modeled – to tailoring the versatile technology for specific applications.

“In some cases, sensors don’t have to be as accurate as the sight, smell, touch, taste and hearing of a person. In others, they can be augmented to far exceed human limitations,” he explains. “And while the human brain remains more efficient and effective at certain operations, such as adding context around sensory data, sensors connected to digital logic can react more quickly and predictably to known stimuli.”
Perhaps not surprisingly, the majority of early vision technology was conducted primarily for medical research purposes, with scientists working to cure blindness and compensate for impaired vision.
“[However], machine vision has a different purpose,” says Sperling. “Rather than striving for visual acuity that is as good or better than a person’s eyesight, current efforts add the ability to sense objects in the non-visible spectra, such as infrared imaging, or radar to detect objects around corners or other objects that are not visible to people.”
According to Steve Woo, VP of Enterprise Solutions Technology at Rambus, the proliferation of next-gen sensors means the growth rate of data will be enormous.
“[Nevertheless], this is [far] more data than can be moved back to the data center. It will require more edge computing, where there will be filters or pre-processing. So you basically can have simple processing to get to more meaningful data,” he says. “You may also start to see more machine learning in the end points, where you scan information and learn the important events about that data and send along consolidated information. There are ways you can do that with reasonable security back and forth over the air.”
As Woo previously told Rambus Press, the rapidly evolving Internet of Things (IoT) has prompted the semiconductor industry to place an emphasis on more efficiently capturing, securing, moving and analyzing an increasing volume of digital data.
“We share the industry’s vision of 50 billion connected devices by 2020, which will also include always-on, always-connected smart sensor endpoints tasked with capturing and delivering a wide range of data.”
Moore’s Law, says Woo, remains a critical factor in making this vision a reality, as the size of refractive imagers is currently limited by optics. Then again, as Sperling points out in the Semiconductor Engineering article referenced above, many applications don’t actually require extensive high resolution imaging capabilities provided by a standard lens-based configuration.
“How can we build even smaller imagers? By replacing the traditional camera lens with a diffraction grating, while leveraging advanced algorithms and chip processing capabilities,” Woo explains. “Now this is where Moore’s Law comes into play, because it continues to help enable the technology necessary for Rambus scientists to create and refine miniature, lensless smart sensors (LSS). While Moore’s Law has been a driving force in the computing industry for decades, we’re seeing a growing number of benefits in computation imaging and sensing applications such as LSS.”
According to Woo, Rambus’ low power sipping sensor technology is capable of performing a wide range of functions, including image change detection, point tracking, range finding, sophisticated gesture recognition, object recognition and image capturing.
“These versatile capabilities make LSS technology suitable for at least five key ‘smart’ verticals, including consumer, cities, transportation, manufacturing and medical,” he adds.
Interested in learning more about the technology behind Rambus lensless smart sensors? You can check out our LSS article archive here.

