Marvell has confirmed that its second-gen 88PA810 Trusted Authentication IC integrates Rambus’ CryptoFirewall security core solution, along with anti-tampering and anti-reverse engineering technologies. Designed for use in systems that require secure product authentication and usage tracking, the 88PA810 provides a proven and trusted offering to prevent counterfeit attacks. The 88PA810 also includes IoT smart device protection against external attacks that threaten vulnerable cloud-connected devices.
Search Results for: IoT security
Rambus CryptoFirewall secures Marvell’s 88PA810 Trusted Authentication IC
Marvell has confirmed that its second-gen 88PA810 Trusted Authentication IC integrates Rambus’ CryptoFirewall security core solution, along with anti-tampering and anti-reverse engineering technologies.
Designed for use in systems that require secure product authentication and usage tracking, the 88PA810 provides a proven and trusted offering to prevent counterfeit attacks. The 88PA810 also includes IoT smart device protection against external attacks that threaten vulnerable cloud-connected devices.
More specifically, Marvell’s 88PA810 security chip features advanced anti-tampering alarms and extensive circuit obfuscations with active metal mesh coverings, internal clocks and regulators. Meanwhile, additional security features prevent attackers from tampering and using physical attack methods to disrupt or copy the chip or its related consumer product.
To be sure, the inclusion of Rambus’ CryptoFirewall technology enables the IC to protect against over 40 attack threats while encrypting off-chip data communications. The 88PA810 also includes secure product authentication services utilizing a unique hardware ID, a secure usage metering count-down counter that cannot be reset and 3KB of one-time programmable (OTP) memory for OEMs to record product information and manufacturing metadata.
Using a traditional inter-integrated circuit (I²C) interface, the 88PA810 connects with a host controller to run authentication and product management services. In addition, the 88PA810 Consumable CryptoFirewall core interfaces with the Verifier CryptoFirewall (VCF) verification core in Marvell’s recently announced 88PA6270 quad-core ARM® Cortex-A53 printer controller SoC. This combined CCF-VCF hardware channel provides hardware-level device authentication to protect against software attacks on the host device.
The 88PA810 – which is currently sampling – also protects the entire supply chain via a multi-stage provisioning solution to eliminate potential risks from rogue elements.
Understanding sensor data and context
Toby McClean recently noted on LinkedIn Pulse that the value of sensor data is lost when each and every device maker or IoT system defines a new model of observation or measurement.
“The value is decreased because third-parties are not able to build reusable algorithms, analytics and visualizations,” he opined. “It is difficult to have reusability when there is no common model for sensor data; for example if every thermometer manufacturer had a different model for temperature.”
In order for it to make business sense for a third-party to build an industry or vertical specific analytics algorithm or visualization, says McClean, it must be able to work with almost all sensors of a particular type.
Patrick Gill, a Principal Research Scientist at Rambus, said one must also understand the context in which sensor data is gathered.
“For example, take an IoT thermometer. It might read the temperature outdoors, indoors, or in the wort of my latest homebrew beer. It’s thus not clear that automatic aggregation of all available temperature data will give useful results,” he explained. “Moreover, we need to understand the privacy and security implications of each piece of data individually. How can each measurement be shared or aggregated? What actuators are allowed to make the data useful without letting crooks know too much about, say, my house occupancy?”
These are all tricky issues, Gill emphasizes, and they potentially may very well have to be addressed differently for every IoT widget out there.
“I would say that looking up the format of the data (so long as the sensor has documentation) is significantly less work than figuring out the use cases of each sensor. Overall, standardizing the data format is not a big concern,” he continued. “I wouldn’t be surprised if some XML schemas turn up in more than one product; however I don’t think that having a standardized data format will remove more than a tiny portion of the work needed to make a compelling and safe IoT product.”
James Tringali, a Technical Director at Rambus, expressed similar sentiments.
“The establishment of common models tends to be driven top down from an ecosystem perspective. Software solution providers sitting atop the ecosystem, such as Google (Nest), Apple and Microsoft, have already crafted XML-like schemas to help their products sort out the sensors that matter to them. Over time, folks bringing in new thermometers, accelerometers, etc. will want to make sure their product’s API play nice with whatever software solution looks to be gaining the most market traction,” he concluded.
Connected vehicles are still vulnerable to hacks
Junko Yoshida, Chief International Correspondent at UBM Electronics, recently reported that the automotive industry is still “ill equipped” to protect connected vehicles from hackers. Indeed, according to a survey conducted by the Ponemon Institute, only 41 percent of developers agreed secure software was a priority for their companies, while 28 percent disagreed.
“Even worse, 69 percent of these developers believe securing applications are difficult/very difficult and nearly half believe that a major overhaul of the car’s architecture is required to make it more secure,” Yoshida wrote in a recent EE Times article. “The survey further revealed that at least 44 percent of the developers queried believe hackers are actively targeting automobiles.”
Perhaps not surprisingly, the survey concluded OEMs and their suppliers “do not yet have the desire, skills, tools or processes to make a secure car.” Nevertheless, companies are not simply sitting back and completely ignoring the problem.
To be sure, 63 percent of respondents confirmed running automated software scans during development, with half executing scans after an application launch and 36 percent conducting penetration tests. Unfortunately, only a quarter of those surveyed said they adhered to secure coding standards and conducted assessments such as threat models.
Egil Juliussen, director research & principal analyst at IHS Automotive, told Yoshida that carmakers – in general – chose complacency over action during the past several years. According to the analyst, specific reasons included “it can’t happen here,” “too much effort for too little reward” and “no known actual breaches.”
Although Juliussen acknowledged successful auto hacking still “requires lots of time and expertise,” he emphasized that “good” hacking tools and expertise would be fielded in three to five years. In the meantime, says Juliussen, “deployment is lagging and may take a decade to catch up.”
Commenting on the Ponemon survey, Craig Rawlings, a Sr. Director of Business Development at Rambus’ Cryptography Research Division, told us that security approaches based on integrated hardware were originally limited to the smartcard space before ultimately expanding to digital content protection and beyond.
“It is interesting to note that movie studios were also considered early adopters –incorporating an integrated hardware and software approach for securing high value video content,” said Rawlings. “With the advent of smartphones and other connected mobile devices, the industry is currently experiencing a new wave of Internet-of-Things (IoT) related security activity.”
Rawlings also noted that Ponemon Institute survey and Yoshida’s EE Times article does a great job of highlighting the importance of robust digital security in the automotive sector.
“It helps make security less esoteric, more real and increasingly tangible. The urgency for security robustness in our cars is made all the more poignant by both the lagging security standards within the automotive industry and the introduction of a new wave of smart, semi-autonomous connected cars,” he added.
Rambus Initiates Accelerated Share Repurchase Program
SUNNYVALE, Calif. ― October 26, 2015 ― Rambus Inc. (NASDAQ:RMBS) today announced it has initiated an accelerated share repurchase program with Citibank, N.A. to repurchase an aggregate of approximately $100 million of its common stock, with an initial delivery of approximately 7,812,500 shares.
“This share repurchase program showcases the confidence we have in our strategic programs and the growth we believe they will ultimately create,” said Dr. Ron Black, president and chief executive officer at Rambus. “We believe this buy-back program highlights our ability to continue the investment in critical technology areas while delivering shareholder value.”
Under the accelerated share repurchase program, Rambus will pre-pay to Citibank, N.A. the $100 million purchase price for common stock and, in turn, Rambus will receive an initial delivery of approximately 7,812,500 shares of its common stock from Citibank, N.A. within the first week of the program. The number of shares to be ultimately purchased by Rambus will be determined based on the volume weighted average price of the common stock during the terms of the transaction, minus an agreed upon discount between the parties. The program is expected to be completed by June 2016. The shares of common stock will be delivered by Citibank, N.A. to Rambus on the third business day following the calculation period described above.
The accelerated share repurchase program is part of the broader share repurchase program previously authorized by the Rambus Board of Directors. As of October 26, 2015, before giving effect to the transaction under the accelerated share repurchase program, there remained an outstanding authorization under the broader share repurchase program to repurchase approximately 20 million shares of the outstanding common stock.
About Rambus Inc.
Rambus creates cutting-edge semiconductor and IP products, spanning memory and interfaces to security, smart sensors and lighting. Our chips, customizable IP cores, architecture licenses, tools, services, training and innovations improve the competitive advantage of our customers. We collaborate with the industry, partnering with leading ASIC and SoC designers, foundries, IP developers, EDA companies and validation labs. Our products are integrated into tens of billions of devices and systems, powering and securing diverse applications, including Big Data, Internet of Things (IoT), mobile, consumer and media platforms. At Rambus, we are makers of better. For more information, visit rambus.com.
Forward-Looking Statements
This release contains forward-looking statements under the Private Securities Litigation Reform Act of 1995 relating, among other things, to the purchase price of shares acquired pursuant to the accelerated share repurchase program, the timing and the duration of prospective share purchases, the amount of cash that may be expended in connection with such share repurchases and the potential growth from our strategic programs. Such forward-looking statements are based on current expectations, estimates and projections, management’s beliefs and certain assumptions made by the Company’s management. Actual results may differ materially. Rambus undertakes no obligation to update forward-looking statements to reflect events or circumstances after the date hereof.
Understanding the changing hardware-software paradigm
Hardware-centric platforms and solutions were traditionally designed with minimal input from software engineers. As Brian Bailey of Semiconductor Engineering recently noted, this approach worked when software content was negligible – and the practice did not significantly contribute to product delays.
“Over time, the software content grew and today it is generally accepted that software accounts for more product expense than hardware, takes longer and adds a significant, if not the majority, of the functionality,” writes Bailey. “Software has [now] become so important that hardware is often seen as the platform needed to optimally support the software.”
Bob Zeidman, president of Zeidman Consulting, expressed similar sentiments.
“Software functionality will determine hardware functionality instead of the other way around,” Zeidman told the publication. “You’ll design software and give performance constraints like cost, power consumption, memory size, and physical size, and the tool will build the hardware design to meet your constraints and run your software.”
Eliott Jones, Rambus VP of User Experience (UX) Eliott Jones, concurred.
“At the end of the day, the product administrators, technicians, and end users engage modern products at the software level. In effect, that experience IS the product to them. What began really with the introduction of the Macintosh way back, where the abstracted layer of the UI was ridiculed by ‘real developers’ has in today’s world of Cloud- and service-based applications become the norm,” he explained during a recent interview with Rambus Press in Sunnyvale. “Whereas traditional hardware survived by being rigidly defined in its function, modern hardware product designs are inherently more versatile, enabling and requiring much more active participation and adaptation to user operation. The outcome is that the software enables user operations to define much more of the total product offering.”
According to Jones, realizing the full potential of a hardware-centric solution is difficult without the inclusion of a well-defined software layer.
“This layer should be built around an intuitive UI that allows the user to easily interact with and act upon meaningful data,” he said. “Historically, most hardware-based products started from the ground up with an emphasis on pure engineering. However, industry expectations have steadily evolved over the years, with enterprise UX standards being set by consumer devices like smartphones and tablets.”
Usability, says Jones, is currently both a key requirement and differentiator.
“Because there is so much data to capture, understand and act upon in today’s world, creating a user experience that distills the data into what’s important at a glance is paramount. The structure and design of controls in software is critical to allow users to understand the meaning of information and to respond to it quickly,” he continued. “Think of it as the difference between a standard BIOS screen circa 1995 – keyboard arrows and all – and a Google Analytics dashboard in 2015. Clearly, software is now a primary, rather than tertiary concern. From my perspective, it would be difficult, if not impossible, to demonstrate a hardware-based platform to potential customers without a truly integrated software layer.”
As Jones points out, that is precisely why Rambus engineers have adopted holistic design cues from consumer-centric products when coding the software for the company’s CryptoManager and DPA Workstation (DPAWS) testing platform.
“As an example, both DPAWS and CryptoManager feature an intuitive UI that integrates advanced visualization capabilities. This helps increase the efficiency of side-channel analysis for the former, while optimizing the Security Engine and related Infrastructure for the latter,” he added.




