Watch this webinar to learn about the components that move, accelerate, and store the data that enable the applications of the future including artificial intelligence (AI), Internet of Things (IoT) and 5G.
Search Results for: IoT
Rambus’ Ben Levine talks IoT security and cryptography with EDA Café
Ben Levine, Senior Director of Product Marketing at Rambus, recently sat down with Sanjay Gangal of EDA Café to discuss IoT security and cryptography. According to Levine, security should be embedded in every chip. More specifically, says Levine, a separate hardware-based security core can help protect both the SoC itself and the system it powers.
“This is particularly important for connected devices,” Levine explains. “Everything is connected to the internet these days – and every device is now exposed to wide range of threats and attackers. So you need really strong security. Devices have also become more complex and challenging to secure.”
Silicon Complexity and Security
The relationship between silicon complexity and security, says Levine, came to the fore with the advent of Meltdown and Spectre in 2018. As we’ve previously discussed on Rambus Press, Meltdown and Spectre were independently disclosed by a number of security experts, including senior Rambus technology advisor Paul Kocher and senior Rambus security engineer Mike Hamburg.
“Modern CPUs are incredibly complex. They are designed to be power efficient and high performance, but not necessarily secure,” Levine elaborates. “Security vulnerabilities happen when components interact in ways designers never thought about. As the number of components and complexity increases, so do interactions and potential security vulnerabilities.”
System designers, says Levine, have to get everything right, although an attacker only needs a single vulnerability to succeed.
“The solution we think makes the most sense is partitioning or siloing security away from other parts of an application that don’t necessarily need to be secure,” he states. “Keys, passwords, identifiers, security, and communications protocols; all of these need to be in a secure domain [secure core]. This domain can be optimized for security and kept relatively simple and straightforward.”
Rambus CryptoManager Root of Trust (CMRT) RT630
The advantage of secure cores, says Levine, is that they can be specifically designed from the ground up to provide robust security. To illustrate an example of a secure core, Levine highlights the Rambus CryptoManager Root of Trust (CMRT) RT630. Built around a custom RISC-V CPU, the CMRT RT630 is at the forefront of a new category of programmable hardware-based security cores.
As Levine explains, the CMRT RT630 is siloed from the primary processor so it can securely run sensitive codes, processes, and algorithms. Moreover, the CMRT provides the primary processor with a full suite of security services, such as secure boot and runtime integrity, remote attestation, and broad crypto acceleration for symmetric and asymmetric algorithms.
The CMRT also helps protect systems against test and debug interface attacks, Power/EM analysis (SPA/DPA), and other side-channel attacks, including timing attacks. Last, but certainly not least, the CMRT supports multiple roots of trust, with hardware ensuring isolation of resources, keys, and security assets. Each entity – such as a chip vendor, OEM or service provider – has access to its own virtual security core and performs secure functions without having to trust other entities.
AI & Quantum Computing
Levine also touches on security threats targeting artificial intelligence (AI) silicon, noting that there were quite a number of AI accelerators in the data center and at the edge. In addition, Levine discusses some of the real-world security risks associated with quantum computing.
“Quantum computing offers a lot of promise. However, asymmetric and symmetric cryptographic algorithms are designed to be secure. Guessing a random key for an AES encryption algorithm [using a conventional computer] would take you [forever],” he elaborates. “However, a quantum computer doesn’t work the same way as [today’s] computers. Asymmetric and symmetric encryption is vulnerable to quantum computing. IBM has said [current] algorithms won’t be secure against quantum computing.”
Rambus, says Levine, has been active in creating a new generation of algorithms that won’t be vulnerable to quantum computing and has submitted its work to the National Institute of Standards and Technology (NIST).
Ben Levine’s full video interview with Sanjay Gangal of EDA Café can be viewed here.
Californian Legislation and IoT
Two identical bills, to be signed by Governor of California Jerry Brown (D), have made provisions for internet-connected devices sold in California, such as thermostats, televisions, and security cameras, would need reasonable security features by January 2020.
The two identical bills would apply to devices that can connect directly or indirectly to the internet and are assigned internet protocol or Bluetooth addresses. Smart home devices, such as Amazon Echo, Google Home, and Apple HomePod would come under the bills’ provisions. The proposals come amidst a rise in privacy and security concerns about Internet of Things (IoT) devices, particularly concerns about data collection from users.

The bills are purposefully vague about what “reasonable security features” refer to in particularly, according to California State Senator Hannah-Beth Jackson (D), who authored one of the bills, S.B. 327. It is up to the manufacturers to decide what steps to take. Another bill, A.B. 1906, authored by Jacqui Irwin (D) is identical to S.B. 327 and both be sent to Governor Brown’s desk to be signed or vetoed by September 30th, 2018. At current, Governor Brown has yet to take a position on the bills.
The responsibility for reasonable security for the devices would be on manufacturers or those who contract with manufacturers who make those kinds of devices offered for sale in California. Exempt from the bill are medical devices and other items subject standards.
Manufacturers argue that the purposefully vague nature of the bill, and would be fodder for litigation, leaving no private right of action. They also contend that the bills do not apply to companies that import and resell connected devices made in other countries under their own labels, potentially opening up a loophole for companies to bypass the law by simply importing other devices.
Opposed to the bills are the Custom Electronic Design and Installation Association, Entertainment Software Association, and National Election Electrical Manufacturers Association. They are sponsored by Common Sense Kids Action and have support from the Consumer Federation of America, Electronic Frontier Foundation and Privacy Rights Clearinghouse, to name a few.
The Bottom Line
State Senator Jackson’s S.B. 327 and Assemblywoman Irwin’s A.B. 1906 have both passed the California State Senate and State Assembly, respectively, and are on Governor Brown’s desk awaiting a signature or a veto by the end of September, 2018. Both bills, identical in language, call for IoT device manufacturers to provide “reasonable security measures” on their devices. However, the purposefully vague language of both bills has raised the concern that companies might be open to litigation through interpretation of such vague language, not to mention the loopholes for companies that import devices from other countries to take advantage of.
A Rise in IoT Spending: Bain and Company’s Findings
According to a new report published by Bain and Company, the combined markets of the Internet of Things (IoT) will grow to about $520 billion in 2021, more than double the $235 billion spent in 2017.
The 2018 survey, which includes purchases of devices, software, and related services, shows that businesses are increasing their appetite for connected devices alongside growing consumer demand for everything from smart speakers to Wi-Fi connected lightbulbs.
There is hope that newer IoT products will have more of their own computing power and artificial intelligence apps built in, making them more independent and efficient, and at least in theory, boosting sales.
Concerns
Since Bain and Co.’s last extensive survey on IoT and analytics two years ago, customers believe that vendors have made little progress on lowering the most significant barriers to IoT adoption – including security, ease of integration with existing Information Technology (IT) and Operation Technology (OT) systems, and uncertain returns on investment. These customers have extrapolated their expectations about when those use cases will reach scale in their organizations. On average, they are planning less extensive IoT implementations by 2020 than they were just a couple of years ago.
However, despite these concerns, enterprise and industrial customers still see success within their reach. They are still running more proofs of concept than they were two years ago, and more customers are considering new use cases, with 60% in 2018 compared with less than 40% in 2016.
Some expected uses of connected devices have not caught on as much as expected. For example, Bain pointed to elevator manufacturer Schindler working with General Electric’s Predix Platform to implement a broad predictive maintenance program designed to optimize maintenance on more than 60,000 elevators and escalators worldwide. The lack of historical data and problems integrating different data formats would make predicting maintenance needs difficult. “Insights have been harder to glean than first promised,” Bain noted.
Overall, the biggest concerns business customers have about IoT remain the same now as in the 2016 survey. Around 42% of companies cited risk of security weaknesses that could allow hackers to infiltrate their computer systems, while another 29% cited difficulties integrating new and old systems, and another 28% feared poor returns on their investment.
The Bottom Line
There is no doubt that the Internet of Thing is a burgeoning industry, with spending doubling that of two years ago, according to a survey by Bain and Company. However, the survey also goes onto indicate that customer expectations of progress still errs on the side of pessimism. There are plenty of new use cases considering the advancement of IoT technology, but in the case of the Schindler/General Electric elevator maintenance program, there is still some ways to go. On top of it all, concern for IoT security is still a serious issue that needs to be addressed if the IoT industry wants to continue to be relevant.
GSMA’s Guidelines and Assessment for IoT Security

A group of wireless carriers worldwide announced in late June that they would adopt and implement standard procedures developed to secure the Internet of Things (IoT). They have committed to implementing the GSMA IoT Security Guidelines, which outline best practices and recommendations for security covering the entire IoT ecosystem.
The carriers involved include AT&T, China Telecom, Deutsche Telekom, Etisalat, KDDI, Orange, Telefonica, Telenor, and Telia. They have also agreed to adopt a comprehensive security assessment scheme to ensure IoT services are protected against security risks. This development comes as GSMA intelligence forecast IoT connections will reach 3.1 billion by 2025.
The CTO of GSMA, Alex Sinclair, said: “for IoT to flourish, the industry needs an aligned and consistent approach to IoT security. Our guidelines encourage the industry to adopt a robust set of best practices that will help create a more security IoT market with trusted, reliable services that can scale as the market grows.”
The Guidelines
According to the GSMA, the guidelines are targeted at IoT service providers, device manufacturers, developers, and mobile operators. Their goal is to address typical cybersecurity and data privacy issues associated with IoT services, and outline a blow-by-blow process to securely launch solutions to market. The guidelines are supported by an IoT Security Assessment scheme, which provides a checklist to support the secure launch of IoT solutions into the market and keep them secure throughout their lifecycles.
Thus, a sustainable IoT ecosystem that is designed for end-to-end security is possible. Both the guidelines and the assessment cover the fast-growing low power wide area (LPWA) or mobile IoT technologies such as Long Term Evolution, Category M1 (LTE-M) and Narrowband IoT (NB-IoT).
“Today it has become imperative to focus on the need to have a common IoT assessment and security guidelines that are adapted by global operators, IoT device manufacturers and developers. With the global opportunity for IoT to grow and enable disruptive innovations, these guidelines will help it to flourish and being adapted across industries and services,” said Francisco Salcedo, Senior Vice President of Etisalat Digital.
The guidelines coincide with the 2018 Mobile World Congress in Shanghai, where IoT security was a prominent theme. In a post-panel interview, Jiang Wangcheng, President of IoT solutions at Huawei mentioned that “IoT security is a serious issue, and government must take the lead on this.” He believes that the government will “take an important role – they can organize companies and create standards,” but he also went onto say that IoT service providers “should secure service quality, including security.”
The Bottom Line
Security issues in IoT have long been ignored or kept to the sidelines. However, in the wake of serious data breaches and attacks, manufacturers and providers are finally waking up to the reality of the need to secure the Internet of Things. The GSMA and the wireless carriers involved have stepped up to the plate, signing up to guidelines and an assessment to ensure that their services are secure. With experts noting the importance of the guidelines, and others noting that the participation of both public and private sectors alike, this development is a positive step forward for IoT security.
The US Department of Homeland Security’s Guidelines for IoT Security
March of 2018 saw the United States Department of Defense (DoD) introduce a guidelines document through the Government Accountability Office (GAO) titled Enhanced Assessment and Guidance are Needed to Address Security Risks in DoD. Two months later, on May 15th, the Department of Homeland Security (DHS) has released a cybersecurity guidelines document of its own, titled US Department of Homeland Security Cybersecurity Strategy.
What the Guidelines Provide For
Its mission statement is to improve national cybersecurity risk management by increasing security and resilience across government networks and critical infrastructure by 2023. Homeland Security hopes to decrease illicit cyber activity, improve responses to cyber incidents, and foster a more secure and reliable cyber ecosystem through a unified departmental approach, strong leadership, and a close partnership with other governmental entities.
The strategy provides Homeland Security with a framework to implement their cybersecurity responsibilities during the next five years to keep pace with the evolving cyber risk landscape. The Department hopes to achieve this by reducing vulnerabilities and building resilience, countering bad actors in cyberspace, responding to incidents, and making the ecosystem more secure and resilient.
The guiding principles for the guidelines are risk prioritization, cost-effectiveness, innovation and agility, collaboration, global approach, balanced equities, and national values.
Enhancing Cybersecurity
John Grimm of Thales e-Security has written that countless devices lack basic security because neither sellers nor buyers are motivated to prioritize it. However, there are organizations connected to industrial and enterprise markets that are motivated to build security into their connected devices. These organizations are seeking clear and actionable guidance, as well as accessible tools and resources to shorten the development curve and facilitate implementation of best practices.
Grimm believes that DHS can have an impact in the aforementioned area, as some of today’s most critical infrastructure was not designed for today’s security environment. On the consumer side, waiting for market dynamics to shift in favor of security will take too long. Fast and direct action is required.
Standardizing Security
The DHS strategy identifies encryption as a challenge to law enforcement, but does not acknowledge the critical role it plays in protecting sensitive personal information of citizens or intellectual property and financial data. With properly understood minimum standards in place, users can know to treat their devices that do not meet them as hostile by default.
The DHS is in a position to encourage and facilitate more awareness throughout the industry. Organizations can work together, without compromising competition, to collectively increase incident preparedness and incident response. Initiatives such as Financial Services Information Sharing and Analysis Center (FS-ISAC) and Automotive Information Sharing and Analysis Center (Auto-ISAC) encourage such collaboration, at least in the financial services and automotive industries. The guidelines from the DHS have noble aspirations in its strategy around awareness and collaboration, but they will be meaningless without action. Secretary of Homeland Security Kirstjen Nielsen said at the RSA conference in April that “the bad guys are crowdsourcing their attacks, so we need to crowdsource our response.”
The Bottom Line
With the DHS joining the DoD and the European Union in laying out documentation for IoT security guidelines, there are signs that more government agencies are beginning to take cybersecurity issues seriously. The DHS guidelines address a number of important areas, including the improvement of cybersecurity for IoT products and minimum standards that all products should meet. Now it is up to the IoT device manufacturers to play ball.


