IoT DevCon 2016 focuses on technologies ranging from the ultra-low power microcontrollers to the multicore-enabled aggregation hubs to the software and security infrastructure required for monitoring and management of the enormous bundles of data
Search Results for: IoT security
Rambus Cryptography Research Unveils Latest Release of DPA Workstation Analysis Platform
Optimized for ease of use and productivity to help identify vulnerabilities to side-channel attacks
SUNNYVALE, Calif. – April 18, 2016 – Rambus Inc. (NASDAQ:RMBS) today announced the release of DPA Workstation 8 analysis platform, featuring an extensive upgrade to the workstation software and user interface for enhanced system performance and usability in ASIC and FPGA side-channel vulnerability testing. Designed to test and analyze hardware and software cryptographic implementations, and to determine vulnerabilities to power and electromagnetic side-channel attacks, DPAWS enables customers to quickly and easily identify and address potential security flaws in tamper-resistant systems and SoCs.
“As the value of data continues to increase, many players in the security industry are taking action to protect their devices from the threat of side-channel attacks,” said Martin Scott, senior vice president and general manager of the Security Division at Rambus. “By using DPA Workstation 8 to analyze and test a device, customers are able to quickly and easily assess any vulnerabilities that an FPGA, ASIC, CPU or microcontroller may have to side-channel analysis, and address them with confidence in their results.”
DPA is a powerful tool attackers use to extract secret keys and compromise the security of tamper resistant devices. It is a side-channel attack that is extremely effective, using variations in the electrical power consumption, or EM emissions, of targeted devices to breach security using statistical methods to derive secret keys from crypto algorithms.
DPA Workstation 8 is a powerful and flexible side-channel analysis platform that features an integrated suite of hardware and data visualization software, aiding in the identification and understanding of vulnerabilities in cryptographic chips. The workstation features a brand new integrated analysis application that includes:
- A project library manager to aid in the rapid analysis of collected data by delivering an integrated view of multiple data sets, scripts and analyses;
- An all new powerful trace display with an intuitive interface for easy analysis; and
- Integrated scripting modules for MatLab and Python to allow for easier analysis and increased productivity.
New features are covered in a comprehensive integrated help utility complete with numerous tutorials and examples. To learn more about the DPA Workstation analysis platform and other DPA Countermeasure solutions, visit rambus.com/dpaworkstation.
Follow Rambus:
Company website: rambus.com
Rambus blog: rambusblog.com
Twitter: @rambusinc
LinkedIn: www.linkedin.com/company/rambus
Facebook: www.facebook.com/RambusInc
About Rambus Cryptography Research
The Rambus Cryptography Research division is dedicated to providing a secure foundation for a connected world. Our innovative technologies span areas including tamper resistance, content and media protection, network security, and secure payment and transaction services. These technologies protect nearly nine billion licensed products annually, providing secure access to data and creating invaluable trust between our customers and their customer base. Additional information is available at rambus.com/security.
About Rambus Inc.
Rambus creates cutting-edge semiconductor and IP products, spanning memory and interfaces to security, smart sensors and lighting. Our chips, customizable IP cores, architecture licenses, tools, services, training and innovations improve the competitive advantage of our customers. We collaborate with the industry, partnering with leading ASIC and SoC designers, foundries, IP developers, EDA companies and validation labs. Our products are integrated into tens of billions of devices and systems, powering and securing diverse applications, including Big Data, Internet of Things (IoT), mobile, consumer and media platforms. At Rambus, we are makers of better. For more information, visit rambus.com.
The evolution of RISC-V and open source
Did you know that many industry pundits originally believed there was “little money” to be made in the business of open source software?
“As the wave of Linux distributions rolled forth, however, that was quickly disproven, setting the decades-long chain of companies that have secured their footing, funding, and futures on the back of open software,” Nicole Hemsoth of The Next Platform wrote in a recent article.

“[This] same trend is moving into hardware, creating what might be the next run for companies touting open source designs. With this is in mind, it is finally time to start to watch one very early stage effort toward open and freely accessible instruction set architectures, most notably RISC-V.”
Of course, whether or not there will be commercial momentum for RISC-V remains to be seen.
“Opportunities for an open source business boom aren’t always expected and come when demand for something truly different is actually feasible,” said Hemsoth. “[Nevertheless], RISC-V in its current incarnation has garnered several backers to the foundation, including Google, LG, BAE Systems, and others.”
Although its commercial future is far from certain, RISC-V is clearly gaining momentum. In addition to the above-mentioned backers, an R&D division of the Indian government is slated to receive approximately $45 million to fund the development of its first 64-bit microprocessor based on the RISC-V instruction set. Meanwhile, a separate team of designers at IIT Madras has been working for more than two years on a family of 32- and 64-bit open source processors based on RISC-V, called Shakti. According to EE Times, the Shakti project now includes plans for at least six microprocessor designs along with fabrics and an accelerator chip.

As we recently noted in “Charting a New Course for Semiconductors,” the success of open-source software – as opposed to a closed, walled-garden approach – has set an important precedent for the semiconductor industry. To be sure, more than 95 percent of today’s web servers run on variants of the Linux operating system, while approximately 85 percent of smartphones sold worldwide use the open-source Android mobile operating system (OS). In addition, Red Hat recently became the first open source company to reach the $2 billion run-rate in annual sales.
According to Steven Woo, VP of Solutions Marketing at Rambus, a number of major industry players would likely be willing to consider backing a new semiconductor paradigm such as RISC-V, particularly when it comes to the Internet of Things (IoT).
“[Of course], it would have to meet certain requirements, and the monetization aspects of such a paradigm would have to be worked out and clearly articulated,” Woo noted in a recent blog post.
Although launching and successfully executing such an initiative wouldn’t be easy, Woo emphasized the idea shouldn’t be dismissed out of hand because of the difficult challenges the industry faces in meeting the promise of the Internet of Things.
“We’ve seen just how much the semiconductor model has changed over the past decade, especially in the mobile space. The semiconductor industry has done a good job of adapting to meet the needs of new markets and applications, and the Internet of Things will be no different,” he added. “With the right level of backing and contributing expertise, RISC-V could provide a foundation for exploring the open source semiconductor model. [More specifically], a RISC-V implementation augmented with security features could allow broad adoption and deployment for a broad range of IoT applications and infrastructure.”
Interested in learning more about RISC-V? You can check out the project’s official page here.
CryptoManager: Between ASICs and FPGAs
Manufacturers typically configure application-specific integrated circuits (ASICS) for targeted use cases. In contrast, a field-programmable gate array – or FPGA – is an integrated circuit with custom logic that is configured by a customer or designer after manufacturing of the underlying FPGA microchip. Although FPGAs offer a number of advantages – including low, non-recurring engineering costs and rapid time-to-market – they also carry a higher unit cost than their ASIC counterparts.
“In-field feature configuration capabilities are clearly an attractive proposition for many in the semiconductor industry. Unfortunately, companies are often forced to forego programmable logic devices (PLDs) due to a significant price differential,” Simon Blake-Wilson, VP of products and marketing for Rambus’ Cryptography Research Division, explained.

“Using CryptoManager, ASIC and ASSP SoCs can be fabbed with highly secure configurable features and/or services within a single chip design – such as in-field provisioning of sensitive data and feature controls – that are typically associated with higher-cost FPGAs. Simply put, these CryptoManager-based SoCs are positioned at the same price as conventional ASICs/ASSPs
SoCs that can be securely configured downstream, says Blake-Wilson, represent the next step in the evolution of silicon and have the potential to redefine the current semiconductor paradigm by unlocking the true — or full — value of chips and extend device lifecycles. Chipmakers already implement limited feature configuration using e-fuses, but such an approach is limited to configuration during chip manufacturing. CryptoManager extends feature configuration throughout the supply chain and into the field.
“This is especially true for higher-end systems, such as those found in semi-autonomous vehicles and at the heart of mobile devices. For example, a recall on some level is currently likely if hackers manage to crack a critical security algorithm in a new electric car,” Blake-Wilson told Rambus Press.

“Such a scenario could be avoided with CryptoManager-based SoCs that drivers manually or automatically update via a cloud-base mobile app. Since CryptoManager-based SoCs are equipped with a hardware root-of-trust, the OTA firmware update would be secure and effective on par with smartcard technologies. There would simply be no need to involve a mechanic, physically rip out systems or conduct a worldwide recall.”
CryptoManager SoCs, says Blake-Wilson, also benefit owners of mobile and IoT devices such as smartphones, tablets and wearables.
“We are essentially asking the end-user: ‘What would you like to do with your chip today?’ By democratizing hardware with an intuitive Features as a Service (FaaS) secure provisioning layer, we are eschewing a one-size fits all approach and allowing consumers to exert greater control over their devices,” he explained. “This effectively means an end to blanket firmware updates. We can offer a more targeted and optimized approach. Want to quickly update your mobile payment capabilities and leave everything else alone? Well, now you can. Want to disable 4G to avoid excessive roaming charges while abroad but find the default software interface confusing? The CryptoManager UI will allow you to do this on a hardware level – so you know 4G is actually switched off.”

According to Blake-Wilson, CryptoManager enabled SoC devices that can be securely reconfigured for specific tasks will also play a major part in building the Internet of Things (IoT). Indeed, as Jim Turley of EE Journal recently reported, developers currently using 8-bit MCUs will soon upgrade to 32-bit units, spurring sales of microcontrollers with licensed processors inside.
“Architects of future smart cities will inevitably design infrastructure equipped with chips in places that are difficult to reach, such as subterranean water pipes, air conditioning ducts and even under roadways,” said Blake-Wilson. “The 32-bit MCUs Turley refers to will need to be ‘future-proofed’ to avoid frequent maintenance, security upgrades and physical upgrades. Using CryptoManager, system architects can significantly extend the lifetime of numerous systems by securely reconfiguring CryptoManager SoC chips – multiple times – to execute new tasks.”
Interested in learning more about CryptoManager? You can check out our official product page here and our article archive on the subject here.
Can semiconductors be open sourced?
Eric Weddington, an Open Source Architect at Trimble, recently published an article on LinkedIn Pulse that examines the possibility of making Integrated Circuits (ICs) and microprocessors open source.
“What would it take to do that? Imagine it would have to take small groups or individuals, perhaps University teams, to get their hands on some semiconductor manufacturing equipment,” he opined. “Perhaps old equipment sold (relatively) cheaply. And methods used to manufacture chips opened up and shared with a community.”

Image Credit: Derrick Coetzee (via Wikipedia)
Improvements to the equipment could be made, says Weddington, with those optimizations ultimately released as open source hardware. However, as Weddington emphasizes, the industry does not (currently) offer any real incentives to make the semiconductor manufacturing equipment cheaper or easier to use.
“Software tools to design chips would [also] have to be created and made open source so the community can use these tools in conjunction with the re-purposed manufacturing equipment,” he continued. “Design libraries would have to be created and open sourced to pull together parts of a chip design for an IC.”
Despite the obstacles, Weddington says integrated circuits could be the “final frontier” of open source.
“Because if it is not, then you can make PCBs on your desktop all day long, but real control of your electronics will always be in the hands of the few,” he added.
Perhaps not surprisingly, Thibault Cantegrel, Director, Developer Program at Sierra Wireless, believes open source hardware could play a major role in helping the Internet of Things (IoT) evolve.
“The Internet of Things has a pressing need to reduce the daunting complexity of building every piece of an IoT solution — the hardware, the embedded software, communications layer, server and associated software,” he explained in an article posted on M2MNow. “This requires a variety of engineering skills. And open source hardware, with such big communities, well designed and well tested hardware pieces would be very compelling if they fit [certain] requirements.”
Indeed, as Michael Cooney of Network World recently pointed out, open source hardware is now roughly in the same place as open source software during the mid-1990s.
“What made open source software acceptable for many businesses was the arrival of support for it, such as Red Hat; something similar may take place with the hardware.”
Steven Woo, VP of Solutions Marketing at Rambus, expressed similar sentiments.
“A number of major industry players would likely be willing to consider backing a new semiconductor paradigm, particularly when it comes to the IoT,” he said. “As Cantegrel notes, it would have to meet certain requirements, and the monetization aspects of such a paradigm would have to be worked out and clearly articulated.”
Although launching and successfully executing such an initiative wouldn’t be easy, Woo emphasized the idea shouldn’t be dismissed out of hand because of the difficult challenges the industry faces in meeting the promise of the Internet of Things.
“We’ve seen just how much the semiconductor model has changed over the past decade, especially in the mobile space. The semiconductor industry has done a good job of adapting to meet the needs of new markets and applications, and the Internet of Things will be no different.”
When asked to identify a potential catalyst that could help spur the adoption of an open source semiconductor model, Woo pointed to the lack of adequate security in the silicon space and a growing interest in effective provisioning.
“With the right level of backing and contributing expertise, RISC-V could provide a foundation for exploring the open source semiconductor model,” he concluded. “A RISC-V implementation augmented with security features could allow broad adoption and deployment for a broad range of IoT applications and infrastructure.”
Interested in learning more about RISC-V? You can check out the project’s official page here.
Rambus Cryptography Research Signs Licensing Agreement with The Athena Group to Accelerate Adoption of DPA Countermeasures
Athena solutions include license to Rambus Cryptography Research countermeasures patents
SUNNYVALE, Calif. – February 29, 2016 – Rambus Inc. (NASDAQ:RMBS) today announced that its Cryptography Research division has signed an agreement with long-term ecosystem partner, The Athena Group, Inc. (Athena), to its patents covering DPA Countermeasures for use in Athena cryptographic security IP cores for field-programmable gate arrays (FPGAs) and defense application specific integrated circuits (ASICs). Athena is a leading provider of security, cryptography, and anti-tamper IP cores with DPA countermeasures that address the insidious security threat of side-channel attacks.
This agreement allows Athena customers to obtain, directly from Athena, advanced countermeasure solutions that rely on Rambus Cryptography Research patents to protect against side-channel attacks. By leveraging these advanced countermeasures implementations, Athena customers can ensure the data integrity of products that run applications requiring a high level of security, particularly those serving the aerospace and defense sectors.
“Securing cores against DPA attacks is a top priority for us and for our customers,” said Monica Murphy, president and chief executive officer of Athena. “This expanded agreement with Rambus enables us to accelerate the adoption of advanced countermeasure solutions designed to counteract that risk. By providing our customers with a license to use Rambus Cryptography Research inventions in connection with our extensive portfolio of cryptographic cores, we can streamline the use model and make it significantly easier for customers to adopt this critical technology. We look forward to directly offering products that embody Rambus’ comprehensive portfolio of countermeasures patents.”
DPA, or differential power analysis, is a type of side-channel attack that monitors variations in the electrical power consumption or EM emissions from a target device. These measurements can be used to obtain cryptographic keys and other sensitive information from semiconductors. Athena DPA countermeasures, in conjunction with Rambus patents, offer a proven solution to warding off these attacks, protecting devices against the extraction of critical, private data.
“Today’s leading manufacturers are looking for solutions to counter the increasing threat of side-channel attacks,” said Paul Kocher, chief scientist of the Rambus Cryptography Research division. “Broader and faster adoption of DPA Countermeasures in the FPGA ecosystem will ensure that components are insulated from these types of vulnerabilities. Athena’s increased ability to rapidly engage and deliver solutions based on our portfolio of DPA countermeasures patents will bring significant benefits to the industries they serve, where safety and security are paramount.”
To learn more about Rambus and the Cryptography Research Division, visit rambus.com/security.
To learn more about Athena, visit athena-group.com.
Follow Rambus:
Company website: rambus.com
Rambus blog: rambusblog.com
Twitter: @rambusinc
LinkedIn: www.linkedin.com/company/rambus
Facebook: www.facebook.com/RambusInc
About Rambus Cryptography Research
The Rambus Cryptography Research division is dedicated to providing a secure foundation for a connected world. Our innovative technologies span areas including tamper resistance, content and media protection, network security, and secure payment and transaction services. These technologies protect nearly nine billion licensed products annually, providing secure access to data and creating invaluable trust between our customers and their customer base. Additional information is available at .
About Rambus Inc.
Rambus creates cutting-edge semiconductor and IP products, spanning memory and interfaces to security, smart sensors and lighting. Our chips, customizable IP cores, architecture licenses, tools, services, training and innovations improve the competitive advantage of our customers. We collaborate with the industry, partnering with leading ASIC and SoC designers, foundries, IP developers, EDA companies and validation labs. Our products are integrated into tens of billions of devices and systems, powering and securing diverse applications, including Big Data, Internet of Things (IoT), mobile, consumer and media platforms. At Rambus, we are makers of better. For more information, visit rambus.com.
About The Athena Group, Inc.
Athena is a leading provider of security, cryptography, anti-tamper, and signal processing IP cores to many of the world’s largest semiconductor companies, defense contractors, and OEMs, as well as emerging providers. Embedded in millions of ASIC and FPGA devices, Athena technologies enable high-value solutions where security and performance are mission critical – defense and aerospace, vehicle safety (V2V, V2X, telematics), networking and communications, satellites, cellular base stations, handsets, the Internet of Things (IoT), and more. For more information, visit athena-group.com.

