On March 21-23 2017, Rambus hosted the first Mobey Forum member meeting of the year in Rotterdam. Over 150 industry experts discussed the meeting’s topic ‘From Payments to a Buying Experience’ including subtopics such as disruption of wallets, IoT, blockchain, biometrics, AI.Host Card Emulation (HCE) technology is making it easier for banks to offer mobile (NFC) payments to their customers. Learn more in this video.
Search Results for: IoT
Understanding the evolution of side-channel attacks
Earlier this month, Christopher Gori, a senior director of product management in Rambus’ security division, wrote an article for Semiconductor Engineering about the evolution of side-channel attacks.
As Gori explains, a side-channel attack can perhaps best be defined as any attack based on information gained from the physical implementation of a cryptosystem, rather than brute force or theoretical weaknesses in the algorithms. To be sure, all physical electronic systems routinely leak information about their internal process of computing via power consumption or electromagnetic emanations. This means attackers can exploit various side-channel techniques to gather data and extract secret cryptographic keys.

“Whether implemented in hardware or software, and regardless of specific instruction set architecture (ISA), most cryptographic security solutions on the market today can be soundly defeated by side-channel attacks,” he writes. “In some cases, secret keys can be recovered from a single transaction clandestinely performed by a device several feet away.”
According to Gori, single-chip devices such as smart cards initially received much of the side-channel attention in the attacker community due to the ubiquity of smart cards in low-end commerce applications and the relatively low cost of such an attack vector. With the side-channel landscape steadily evolving over the years, attackers are now capable of compromising a wide variety of vulnerable targets such as aerospace and defense systems, vehicles, set-top boxes and even implanted medical devices.
As more devices are connected to the Internet of Things (IoT), says Gori, proactive suppliers have begun to place more of an emphasis on security by offering integrated countermeasures to their customers.
“[This is because] devices without countermeasures are frequently vulnerable to Differential Power Analysis (DPA), a category of noninvasive side-channel attack. Effective DPA resistance cannot be achieved by chance, or even by the default complexity or high clock frequency of a target device,” he explains. “Therefore, measurable and quantifiable security standards, such as those offered by Test Vector Leakage Assessment (TVLA) methodology, are essential to shielding devices and systems from side-channel attacks, as untested and unverified countermeasures are typically ineffective.”

Specific DPA countermeasure techniques, says Gori, include decreasing the signal-to-noise ratio of the power side channel by reducing leakage (signal) or increasing noise, for example, by making the amount of power consumed less contingent upon data values and/or operation (balancing); introducing amplitude and temporal noise; incorporating randomness with blinding and masking by randomly altering the representation of secret parameters and implementing protocol-level countermeasures by continually refreshing and updating cryptographic keys used by a device.
“Device vendors can either implement countermeasures themselves or choose from several commercial software and hardware offerings that provide side-channel resistant for commonly used cryptographic offerings,” he adds. “For device makers implementing DPA countermeasures, it is recommended that the system and device prototypes be evaluated for resistance to side-channel attacks – such as SPA, CPA, DPA, HO-DPA and their electromagnetic equivalents – before a product is brought to market.”
Interested in learning more? You can check out our DPA countermeasures page here.
Enhancing the buying experience at Mobey Forum Rotterdam
Written by André Stoorvogel, Director, Product Marketing, Rambus Payments
Last week we hosted Mobey Forum’s largest ever member meeting at our Rotterdam office. We were thrilled to welcome organizations and experts from around the world for three days of invaluable networking and industry insights.
We’ve taken a moment to reflect on some of the key topics, and explore how they might impact the payments and retail industries in 2017.

From payments to buying experiences
As the core theme of the Rotterdam meeting, this transition is something the speakers were passionate about. So while mobile payments were still a hot topic, the conversation had moved on from the enabling technology to the consumer interface. For many speakers, including myself and our CEO Ron Black, getting closer to the consumer by providing a better user experience will only become more important as unified payments (combining gift cards, points, coupons and credit into a single transaction) become fully integrated into consumers’ day-to-day lives.

Attendees also heard up-to-the-minute examples of organizations enabling a move towards a holistic buying experience, including PayKey’s secured payment keyboard that facilitates payments directly from a bank account on social media channels, and Paytogether’s payment gateway that enables consumers to make group bookings in a single transaction. Convenience, simplicity and value; everything needed to drive adoption.
AI, blockchain and HCE hit their stride
Artificial intelligence (AI) has also been a popular topic of discussion in recent years, and we are starting to see use cases in fintech. In Rotterdam we had the opportunity to discuss the potential value of AI in banking, and it is going to be exciting to see how this emerging technology can add value to banks and consumers. In a rapidly evolving ecosystem like payments, it’s always difficult to make predictions, but we are confident that AI will continue to develop its presence in the industry.
Interesting discussion also centered on the application of technologies that improve connectivity, security, user experience and engagement within mobile payments. Blockchain, the most talked-about tech in 2016, continues to show incredible promise – Consult Hyperion in particular were enthusiastic about how it could be used outside of B2B transactions, where much of its coverage has focused. Bluetooth, a technology that at one point nearly faded into the past, was also discussed at length, having risen to prominence once more with the growth in wearables and IoT devices. Beyond this, discourse around augmented reality also showed that all of these technologies are being combined to bring us closer to a seamless, frictionless and invisible buying experience.
Working together to add value to payments
This is arguably the most exciting period in the history of payments and many of the companies leading the way are doing so collectively. For example, we heard about Mastercard and Samsung’s collaboration to develop Groceries, the first shopping app integrated into a refrigerator, which learns from shopping habits to make personalized suggestions. On top of this, Masterpass technology is also being leveraged in the automotive industry, with General Motors and IBM working together to develop the first cognitive mobility platform for connected cars.

Another mobile payment technology that was discussed at length during the meetings was host card emulation (HCE). While no longer a new technology, realizing its full potential centers on certification, as FIME and Riscure explained. Certifiable standards in mobile payments technologies allow not just for interoperability and multi-device functionality, but also make collaborations between different members of the payments ecosystem possible.
Conclusions
The payments sector continues to explore new ways to improve the customer journey. We are proud to be a part of the evolution towards a buying experience that truly adds value for consumers, banks and retailers. After participating in last week’s meetings, there is no doubt in my mind that much of the innovation and collaboration happening already across the industry (and much we are yet to see) is born in gatherings like Mobey Forum Rotterdam.
What to expect: Mobey Forum Rotterdam
Written by André Stoorvogel, Director, Product Marketing, Rambus Payments
As a leading FinTech hub, there’s no better setting than Rotterdam for the industry’s experts to share ideas, insight and experiences. This is why we are excited to welcome some of the biggest names in payments to our Rotterdam offices for the first Mobey Forum member meeting of 2017. Keynotes, expert tables, panels and workshops are all on the agenda, with the discussion centering on how we get ‘From Payments to a Buying Experience’.

Our CEO, Ron Black, will open proceedings with a discussion on ‘Envisioning the Buying Experience: What and How.’ Members attending the forum will also hear from multiple industry experts from banks and service providers such as ING, BKM, OP Bank, FIME Aite Group, UL, Strands, MasterCard and CaixaBank, who will share their insights on a range of topics related to payments and the buying experience. The Mayor of Rotterdam, Ahmed Aboutaleb, will also welcome members to a networking dinner, drawing the first day of the member meeting to a close.
Throughout the event, expert table discussions will provide Mobey Forum members with the opportunity to exchange experiences and ideas with likeminded financial professionals, including a discussion led by Rambus Payments’ Martin Cox on the ‘Future of Payments & PSD2’. We are also looking forward to IoT Academy of Rotterdam’s interactive workshop on developing Internet of Things applications in their portable lab and experiencing what the future of payments will look like. Then I am pleased to have the opportunity to close the event by exploring how we expect to pay in 2020.
Not only will Mobey Forum attendees gain insights and information that simply cannot be Googled, they will be able to share experiences and solve problems together, providing great opportunities for networking and collaboration. We look forward to hosting everyone in Rotterdam, one of the coolest cities and FinTech hub!
Check out the agenda now!
Ransomware families spike 752%
Trend Micro has confirmed a 752% increase in ransomware families during 2016, with spam ranked the top infection vector. According to the cyber security company, the availability of open source ransomware and ransomware-as-a-service (RaaS) will continue to make it easier for cyber criminals to run their own ransomware operations.

Image Credit: Trend Micro
“Organizations should therefore stay vigilant to avoid losing data and money and experiencing significant system downtime,” Trend Micro researchers recommended.
As ZDNet’s Danny Palmer notes, it takes only seconds for ransomware to block access to an entire network. Nevertheless, most businesses remain locked out of crucial files and systems for a week or more, with the impact causing severe financial and reputational damage.
“Data gathered [by Timico and Datto] from over a thousand businesses which have been victims of ransomware within the last year suggests that 85 percent of those infected by the malicious file encrypting software had their systems forced offline for at least a week, while a third of cases resulted in data being inaccessible for a month or more,” he explained. “Worryingly, 15 percent of those targeted with ransomware found that their data was completely unrecoverable.”
According to Asaf Ashkenazi, senior director of Product Marketing at Rambus, ransomware has become everyone’s problem.

“To cyber criminals, nearly every device is a potentially lucrative target – not just critical infrastructure like an electric company, or big businesses, universities, public transportation systems and hospitals,” he explained in a recent Seminconductor Engineering article. “Therefore, implementing an effective security solution must be a priority, even for mid-size and small businesses.”
As Ashkenazi emphasizes, security solutions should be ready out of the box: simple, affordable and easy to use.
“This is even more [critical] for IoT devices and their cloud services,” he continued. “One way of simplifying security and reducing costs is using IoT devices with a tamper-proof pre-provisioning key and identifier, which enable out-of-the-box secure connectivity and other security features. That allows service providers to bolster security for a wide range of connected ’things.’”
Ashkenazi also points out that mass adoption of ‘plug and play’ security solutions by IoT OEMs and IoT platform providers will allow small and medium businesses to easily and affordably adopt security, which will hopefully act as a positive catalyst to change the current status quo when it comes to unchecked ransomware activities by cyber criminals.
“Minimizing the number of unprotected endpoints can help reduce the success rate of ransomware, hopefully discouraging cyber criminals from participating in an increasingly unprofitable business,” he concluded.
Protecting the physical world from the digital realm
Written by Asaf Ashkenazi
Industry estimates suggest the global cyber insurance business could reach approximately $20 billion by 2020. Currently, most cyber insurance policies cover damages related to data leaks, such as the inadvertent publication of SSNs, bank account or credit card numbers and patient medical history. Other cyber insurance policies offer compensation for ransomware payments.

The industry is also preparing itself for actual physical damage caused by cyber criminals. This is because Internet of Things (IoT) devices connect the physical world with the digital realm. Hijacked IoT devices and systems can potentially cause significant damage and are a huge liability if they remain unprotected. For example, in 2015, cyber criminals targeted a steel mill in Germany, manipulating and disrupting various control systems. According to Wired, a blast furnace in the mill could not be properly shut down, resulting in “massive” (though unspecified) damage.
Perhaps not surprisingly, Booz Allen Hamilton warns that the impact of cyber-attacks against Industrial Control Systems (ICS) could be devastating.
“Attacks can cause extended operational halts to production and physical damage and even jeopardize the safety of employees and customers,” the organization stated. “The attack surface for ICS is larger than just the ICS devices, equipment and networks: It extends to all parts of an organization, including the extended supply chain.”
One basic premise of any insurance policy is the ability to precisely assess risk versus potential damage. Clearly, the risk for cyber security insurance that covers physical damage caused by a cyber attack will be negatively affected by the extent of the attack vector. This vector is also represented by the number of connected endpoints and the physical damage each IoT endpoint can potentially cause if compromised.
Increased risk, incurred by unprotected endpoints, will inevitably result in higher policies, deductibles and other limitations that makes cyber insurance all but unaffordable for many businesses. Moreover, insurance companies could potentially require proof of specific security measures taken by the policy owner to reduce the risk of attacks. In the future, insurance companies may also demand their policy holders implement a certain level of security before coverage begins.
From our perspective, reducing the IoT attack surface starts with adequately protecting both services and endpoints. It is important to note that an attacker cannot compromise an endpoint without first establishing an unauthorized communication channel. An IoT security solution should therefore only allow legitimate, verified cloud services to ‘talk’ with each device by detecting and thwarting unauthorized communication attempts. In addition, IoT devices should be uniquely and cryptographically verified to determine if they are authorized to connect, thereby reducing the attack surface of the service by preventing remote attacker access directly or through malicious or compromised endpoints.
In conclusion, the industry must prepare for a new era in which IoT security solutions adequately protected the physical world from the digital realm.



