The RSA 2015 Cryptographers’ Panel in San Francisco featured a number of prominent security personalities such as Adi Shamir, Ed Giorgio, Ronald Rivest and Whitfield Diffie. Moderated by Paul Kocher, the President and Chief Scientist of Rambus’ Cryptography Research Division, the panel touched on a wide range of topics, including E.M.V. smart credit cards, the Internet of Things (IoT) and ransomware.
Search Results for: IoT security
Cryptographers take on security challenges @ RSA2015
The RSA 2015 Cryptographers’ Panel in San Francisco featured a number of prominent security personalities such as Adi Shamir, Ed Giorgio, Ronald Rivest and Whitfield Diffie.
Moderated by Paul Kocher, the President and Chief Scientist of Rambus’ Cryptography Research Division, the panel touched on a wide range of topics, including E.M.V. smart credit cards, the Internet of Things (IoT) and ransomware.
“Massive growth during the Industrial Revolution posed a number of significant challenges for society,” said Kocher, who kicked off the panel in front of a packed auditorium. “We face a similar issue today when it comes to technology, particularly around security and how to manage risk.”
Image Credit: RSA Conference
Rivest, the Vannevar Bush Professor of Computer Science at the Massachusetts Institute of Technology, expressed similar sentiments by drawing an analogy to the Cambrian explosion 542 million years ago, when life on earth evolved very rapidly.
“All of a sudden, the planet Earth was suffused with light,” he said. “Animals can now see long distances, significantly altering the relationship between predator and prey. This is a good analogy for the current security situation today.”
Adi Shamir, who specializes in cryptographic schemes and protocols, agreed that newer technologies and products related to the rapidly expanding IoT were vulnerable if not properly secured. However, the Borman Professor of Computer Science at the Weizmann Institute in Israel also emphasized that the more things changed, the more they actually stayed the same.
To illustrate his point, Shamir reiterated his “three laws of security” which, although formulated by the cryptographer back in the 1980s, remains extremely relevant today.
“Firstly, secure systems do not exist today or in the future. Secondly, cryptography will not be broken, but bypassed. Thirdly, to halve the vulnerability you have to double the cost,” he explained. “Trying to stop the most sophisticated attacks means companies have to spend lots of money. This is why some have chosen to adopt a ‘good enough’ approach to security.”
More specifically, says Shamir, some of the new IoT products offer less than stellar security. Indeed, one recently tested demo system was found to have (temporarily) unsecured WiFi during the configuration – a major vulnerability that could allow attackers to steal passwords and gain access to the network.
In addition to exploring IoT security challenges, the cryptographers discussed the recent adoption of the E.M.V. smart credit card standard in the United States. While the new cards are likely to deny cyber criminals one of their most lucrative strategies, no one expects them to throw in the digital towel anytime soon.
Indeed, as Kocher noted in a recent New York Times op-ed, cyber criminals will shift to other lucrative (though somewhat less attractive) ways to profit from stolen data and credentials, such as stealing from brokerage accounts, forging checks, filing bogus tax refunds and engaging in insider trading and medical billing schemes.
“The E.M.V. roll-out is a critical first step, but it will take a long time to shift our critical security tasks away from complex microprocessors and their software to simpler, well-isolated circuits and chips built for security,” he added. “More systems will get attacked and then upgraded, technical advances will create new and greater opportunities for abuse, and the cycle will continue.”
Ransomware was another area of concern for the panel, with KEYW cryptographer and security expert Ed Giorgio emphasizing that once cyber criminals gain access to a system and hold specific files hostage, they are likely to look around for something else to blackmail a victim with.
“Ransomware [is lucrative] and will be around as long as they can make [victims] pay money and maintain their ability to extort,” he concluded.
Interested in learning more about Rambus’ activities at RSA 2015? Be sure to check out booth S1815 on the exhibit floor, where we will be showcasing CryptoFirewall and a wide range of DPA countermeasure solutions. You can also follow us on Twitter for live show updates.
Athena Security IPs Designed to Mend Holes in SoCs
The need to protect connected systems — cars, mobile phones, smart grids, connected factories and any other IoT devices — by using security chips with crypto keys is growing rapidly, while not clearly answering a critical question: How do we know if the security chips designed into such connected systems aren’t leaking key information?
Understanding the supply chain security conundrum
Writing for Semiconductor Engineering, Ernest Worthman describes the challenge of securing chips as a “foot race” between the good and bad guys.
“Going forward, expect heavily funded, grouped efforts to place tremendous pressure on security envelopes,” Worthman explains.
“This includes everything from simple home devices, such as routers, to the most critical infrastructures, such as power, telecom, transportation, and soon, the IoT.”
As Worthman notes, the number one challenge is convincing the entire industry supply chain to acknowledge the value of security. According to Paul Kocher, president and chief scientist at the Rambus Cryptography Research Division, revisiting chip speed and cost is just one paradigm that will have to be re-examined in this context.
“We have solved the first, elementary problem of making chips acceptably fast and acceptably cheap to manufacture. We have gotten really good at exercising that optimization muscle,” Kocher told Semiconductor Engineering.
“[Nevertheless], there are some issues that we need to look at, around security that will require sacrificing some of the gains we have made, in terms of speed and cost. This will certainly present some new engineering challenges as well as cultural challenges.”
One specific area identified by the Rambus chief scientist is one where mature devices work well with minimal innate security – with function and cost having been optimized at the expense of security.
“Such devices function reasonably well, but the failure modes are uncertain or complicated, especially when it involves design or human errors,” he continued. “One way to address this is to take a calculation and, rather than one piece of circuitry do it, have two pieces of circuitry do it. Each circuit can use separate approaches. If they don’t yield the same answer, then something is wrong.”
Another area of IC security flagged by Kocher is the manufacturing process, which faces the challenge of developing viable solutions to make factory environments with untrusted elements more secure.
“For networks that are tightly monitored, you don’t really want the [security] keys to be part of monitoring data, or having the test tractions being sent over to whomever is managing the secrets for the process,” he said.
“[However], there are solutions that can be implemented, such as applying a Diffie-Hellman key exchange scenario. The fact that such solutions can be done, mathematically, has been known for a long time, but the engineering to bring such capabilities into mainstream manufacturing hasn’t, for the most part, actually been implemented in chip factories.”
As Kocher emphasizes, successfully making the case for robust security remains a significant hurdle all along the supply line.
“The [primary] challenge is how to make the security technology help everyone from the chip manufacturer to the end user,” he added.
The 2025 security UX
It’s a chilly, overcast winter day in Seattle. Freezing rain drizzles from trademark gray skies, pattering gently against the glass windows of a local coffee shop. Sitting alone at a dimly lit table, Mia takes one last sip of espresso from a worn, chipped mug before donning her glasses and jacking into a Virtual Security Dock (VSD).
Mia – a white hat bounty hacker – scans the interactive dock for job postings, eyeing a lucrative intrusion detection and prevention system (IDPS) challenge before selecting a pair of tablet-based side channel attack analyses.
Seconds later, she is poring over a torrential river of raw data, probing for potentially critical vulnerabilities to a wide variety of attacks, including timing, electromagnetic, acoustic cryptanalysis and differential fault analysis.
Struggling to make sense of the information overload, Mia enables VSD’s enhanced visualization mode. Disparate streams of data coalesce into coherent patterns, allowing the digital bounty hunter to identify several possible weaknesses along a relatively robust security perimeter.
Sounds like science fiction? Well, a future dominated by advanced VR tech may be closer than it appears. Indeed, Gartner research director Brian Blau recently confirmed that interest in head-mounted displays, which power virtual reality (VR), augmented reality (AR) and other smartglass apps, is set to increase significantly.
To be sure, the technology behind HMDs will be used in a variety of consumer and business scenarios by 2018.
“HMDs [were] more popular in 2014 than at any point in the past. Prior to 2014, HMDs were mainly found in specialty applications, such as industrial design or military training and simulation, where HMD technology is well-developed,” Blau explained.
“However, even with a long history of HMD development, broad adoption in the consumer market has yet to take hold. That situation will change as soon as HMDs are offered as stylish, consumer-grade video eyeglasses. This will eventually drive adoption when paired with compelling virtual worlds and augmented real-world content.”
Eliott Jones, VP of User Experience at Rambus, echoes Wilson’s assessment.
“As with other technology and devices, the popularity of HMD amongst mainstream consumers will act as a catalyst for enterprise adoption. In particular, security researchers can be expected to benefit from a new way of visualizing and interacting with complex datasets,” said Jones.
“It is important to note that effectively extracting meaning from a vast amount of captured raw security-related data requires engaging a broader range of perceptual processing in the brain that goes beyond alpha-numeric information. In this case a highly visual and intuitive user interface (UI) enables the user to absorb information and process it with extreme cognitive efficiency. This combination of multi-sensory experience and an intuitive design creates an integrated, meaning driven – rather than information driven – analytic environment which serves to optimize a platform’s efficiency and ultimately helps define its competitive advantage.”
According to Jones, HMDs should be viewed in the context of the rapidly evolving Internet of Things (IoT). As we’ve previously discussed on Rambus Press, modern UI technologies for the IoT strive to engage the range of a user’s senses by incorporating evolved design principles that facilitate simple, more natural methods of interacting with the environment.
Specific examples, says Jones, include electric cars that can be programmed, monitored and controlled remotely via a simple mobile app; personalized home environments that are configured and regulated from any location; phone calls handed off seamlessly from one device to another as the user moves from the office to the car; and social, crowd-sourced driving experiences powered by real time traffic feedback.
Interested in learning more about the IoT and UX? You can check out some of our previous articles here, including “Making sense of Big Data in the age of the IoT” here, “Understanding the IoT’s evolving requirements” here, “Why intuitive interaction with visual data is critical for security” here and “The UX matters for the Internet of Things” here.
Why intuitive interaction with visual data is critical for security
Writing for InformationWeek’s Dark Reading, OpenGraphiti creator Thibault Reuille says the security field offers an “endless number” of applicable uses for the visualization of loosely related data.
“Firewall, intrusion detection and prevention systems (IDS/IPS) and malware infection alerts could, for instance, be visualized to expose a malicious actor’s previously unrecognized activity patterns,” he explains.
“By processing and analyzing very large log files, data visualization can help summarize and simplify the current state of a complex IT system in an accurate and elegant fashion.”
Reuille, who works as a security researcher at OpenDNS, also notes that smart data visualization, combined with intelligent data mining, “holds the key to better understanding and solving the complex problems security researchers face today.”
Eliott Jones, VP of User Experience at Rambus, concurs with Wilson’s assessment.
“Effectively extracting meaning from a vast amount of captured raw security-related data requires a highly intuitive user interface (UI) paired with enhanced visualization,” says Jones. “This combination creates an integrated meaning driven – rather than information driven – analytic environment that serves to optimize a platform’s efficiency and ultimately helps define its competitive advantage.”
As Jones points out, cutting-edge UI technologies for mobile devices and the Internet of Things (IoT) successfully engage a wide range of the user’s senses by facilitating simple, more natural methods of interacting with the environment that bring data to a human scale. At that point, it is both meaningful and actionable.
“That is precisely why Rambus engineers adopted design cues from consumer-centric products when developing the software layer of our DPA Workstation testing platform (DPAWS),” Jones continues. “To be sure, the current DPAWS software layer boasts an intuitive UI that integrates advanced visualization capabilities to bolster the efficiency of side-channel analysis.”
As we’ve previously discussed on Rambus Press, DPAWS evaluates resistance to a variety of side-channel attacks (SPA, DPA, HO-DPA and EMA) across multiple devices and platforms including smartphones, tablets, PoS terminals, CPUs, TVs, set-top boxes, FPGAs, smart cards and NFC tech.
Essentially, side-channel attacks are low-cost, non-invasive methods that enable attackers to extract secret cryptographic keys from electronic devices used during normal device operations.
DPA Countermeasures, developed by the Cryptography Research division of Rambus, feature a combination of software, hardware and protocol techniques designed to protect tamper-resistant devices from side-channel attacks. These include leak reduction, incorporating randomness, generating amplitude and temporal noise, as well as executing protocol-level countermeasures.
Perhaps the most effective method of thwarting side-channel attacks is to start with the core itself. Rambus offers both AES-128 and AES-256 cryptographic cores, both of which are fully capable of resisting both first– and second– order DPA attacks up to 10 million traces. The cores can also be optimized based on size, speed and security level requirements.
Interested in learning more? You can read about our DPA countermeasures here, check out our DPA resistant cores here and browse our extensive security archive here.





