The RSA 2015 Cryptographers’ Panel in San Francisco featured a number of prominent security personalities such as Adi Shamir, Ed Giorgio, Ronald Rivest and Whitfield Diffie. Moderated by Paul Kocher, the President and Chief Scientist of Rambus’ Cryptography Research Division, the panel touched on a wide range of topics, including E.M.V. smart credit cards, the Internet of Things (IoT) and ransomware.
Search Results for: IoT
Cryptographers take on security challenges @ RSA2015
The RSA 2015 Cryptographers’ Panel in San Francisco featured a number of prominent security personalities such as Adi Shamir, Ed Giorgio, Ronald Rivest and Whitfield Diffie.
Moderated by Paul Kocher, the President and Chief Scientist of Rambus’ Cryptography Research Division, the panel touched on a wide range of topics, including E.M.V. smart credit cards, the Internet of Things (IoT) and ransomware.
“Massive growth during the Industrial Revolution posed a number of significant challenges for society,” said Kocher, who kicked off the panel in front of a packed auditorium. “We face a similar issue today when it comes to technology, particularly around security and how to manage risk.”
Image Credit: RSA Conference
Rivest, the Vannevar Bush Professor of Computer Science at the Massachusetts Institute of Technology, expressed similar sentiments by drawing an analogy to the Cambrian explosion 542 million years ago, when life on earth evolved very rapidly.
“All of a sudden, the planet Earth was suffused with light,” he said. “Animals can now see long distances, significantly altering the relationship between predator and prey. This is a good analogy for the current security situation today.”
Adi Shamir, who specializes in cryptographic schemes and protocols, agreed that newer technologies and products related to the rapidly expanding IoT were vulnerable if not properly secured. However, the Borman Professor of Computer Science at the Weizmann Institute in Israel also emphasized that the more things changed, the more they actually stayed the same.
To illustrate his point, Shamir reiterated his “three laws of security” which, although formulated by the cryptographer back in the 1980s, remains extremely relevant today.
“Firstly, secure systems do not exist today or in the future. Secondly, cryptography will not be broken, but bypassed. Thirdly, to halve the vulnerability you have to double the cost,” he explained. “Trying to stop the most sophisticated attacks means companies have to spend lots of money. This is why some have chosen to adopt a ‘good enough’ approach to security.”
More specifically, says Shamir, some of the new IoT products offer less than stellar security. Indeed, one recently tested demo system was found to have (temporarily) unsecured WiFi during the configuration – a major vulnerability that could allow attackers to steal passwords and gain access to the network.
In addition to exploring IoT security challenges, the cryptographers discussed the recent adoption of the E.M.V. smart credit card standard in the United States. While the new cards are likely to deny cyber criminals one of their most lucrative strategies, no one expects them to throw in the digital towel anytime soon.
Indeed, as Kocher noted in a recent New York Times op-ed, cyber criminals will shift to other lucrative (though somewhat less attractive) ways to profit from stolen data and credentials, such as stealing from brokerage accounts, forging checks, filing bogus tax refunds and engaging in insider trading and medical billing schemes.
“The E.M.V. roll-out is a critical first step, but it will take a long time to shift our critical security tasks away from complex microprocessors and their software to simpler, well-isolated circuits and chips built for security,” he added. “More systems will get attacked and then upgraded, technical advances will create new and greater opportunities for abuse, and the cycle will continue.”
Ransomware was another area of concern for the panel, with KEYW cryptographer and security expert Ed Giorgio emphasizing that once cyber criminals gain access to a system and hold specific files hostage, they are likely to look around for something else to blackmail a victim with.
“Ransomware [is lucrative] and will be around as long as they can make [victims] pay money and maintain their ability to extort,” he concluded.
Interested in learning more about Rambus’ activities at RSA 2015? Be sure to check out booth S1815 on the exhibit floor, where we will be showcasing CryptoFirewall and a wide range of DPA countermeasure solutions. You can also follow us on Twitter for live show updates.
Athena Security IPs Designed to Mend Holes in SoCs
The need to protect connected systems — cars, mobile phones, smart grids, connected factories and any other IoT devices — by using security chips with crypto keys is growing rapidly, while not clearly answering a critical question: How do we know if the security chips designed into such connected systems aren’t leaking key information?
Rambus CryptoManager highlighted @ GSA Silicon Summit
Dr. Martin Scott, the senior VP and GM of Rambus’ Cryptography Research Division, recently participated in a Silicon Summit Internet of Things (IoT) panel hosted by the Global Semiconductor Alliance (GSA). Additional speakers included Rahul Patel of Broadcom, James Stansberry of Silicon Labs and Gregg Bartlett of Globalfoundries.
Rambus CryptoManager highlighted @ GSA Silicon Summit
Dr. Martin Scott, the senior VP and GM of Rambus’ Cryptography Research Division, recently participated in a Silicon Summit Internet of Things (IoT) panel hosted by the Global Semiconductor Alliance (GSA). Additional speakers included Rahul Patel of Broadcom, James Stansberry of Silicon Labs and Gregg Bartlett of Globalfoundries.
“The industry has undergone significant changes over the past 30 years. We now live in an exciting new world, one where everything is connected, with 50 billion connected devices expected by 2020,” Scott told conference attendees.
“However, it is important for us to address the inevitable security vulnerabilities that go along with the rapid deployment of smart edge nodes and sensors. According to IDC, 90% of all IT networks will have an IoT-based security breach within two years.”
To make matters worse, says Scott, there is fresh motivation for those seeking IoT-related vulnerabilities.
“Money, greed and the desire for power are some of the usual suspects, although there are also people who are interested in exploiting security vulnerabilities and causing national harm as a way to express an ideology,” he continued. “The good news? Silicon, in the form of a hardware-based root-of-trust, can go a long way in helping to secure the IoT.”
As Scott notes, all endpoints are not created equal.
“Obviously, a refrigerator isn’t analogous to critical national infrastructure such as a power grid or pumping station. Nevertheless, the security of any complex system is defined by its weakest link,” he explained. “Imagine if someone gained unauthorized access to a home WiFi network via a smart refrigerator or washing machine. Once on the network, an attacker could theoretically assume control of a wide range of sensitive devices and systems, including pacemakers, insulin pumps and even connected cars.”
If a system relies on software, says Scott, it is inherently hackable. In contrast, a hardware-based approach, such as one offered by Rambus’ CryptoManager, is one of the most secure ways to protect sensitive keys, data and infrastructure. As we’ve previously discussed on Rambus Press, CryptoManager was designed to bolster both efficiency and security at the very beginning of the supply chain.
Indeed, the CryptoManager Security Engine can best be described as a silicon core integrated into a SoC that provides a hardware-based root-of-trust for the secure provisioning, configuration, keying and authentication of SoCs during chip and device manufacturing.
Meanwhile, the CryptoManager Infrastructure includes hardware appliances to automate and secure in-factory operations for the protection, distribution and authorization of cryptographic keys at all levels of the chip manufacturing processes.
In addition to helping address security needs for advanced mobile devices, CryptoManager enables a number of features, including dynamic provisioning for cost effective device personalization. Simply put, CryptoManager provides a single UI across factory locations, real-time visibility into operations and remote feature activation.
This means chip and handset makers can meet device personalization demands, reduce operating costs and accelerate time-to-market. Mobile device manufacturers can also more efficiently align the IC supply chain with future demand for diverse smartphone features – all while ensuring the security of secret keys and sensitive data.
Interested in learning more about CryptoManager? You can check out our official product page here, read a recent IDC analysis about the platform here and browse our CryptoManager article archive here.
M2MNow features Rambus lensless smart sensors (LSS)
Writing for M2MNow, Matt Hatton notes that Rambus lensless smart sensors (LSS) use diffraction gratings – rather than traditional camera lenses – to partially focus inbound light.
“[LSS leverages] processing power and smart algorithms to turn this light into information,” he explains.
“This might include turning it into something much more like a conventional picture, but it need not – particularly if the point of gathering the data was to produce the information rather than pictures.”
As Hatton points out, the Rambus LSS approach represents a “conscious departure” from the human eye paradigm.
“The conventional approach to image capture is essentially to use a lens to focus a light array on to something sensitive. Rambus’ alternative is to throw processing power at the light array rather than to rely on a lens to improve the acuity of the image that is captured,” he continues.
“Lensless sensors are cheaper than their camera equivalents; a conventional lens-based camera-like sensor can cost anywhere from USD1 to USD10. They can also be much smaller, by a factor of around 50; and they also require less power.”
Some of these advantages, says Hatton, are due to the fact that LSS can be specifically designed for a single purpose or use case – and are not limited to a more ‘horizontal’ approach implicit in a lens-based camera.
“This kind of sensor thus places less demand on both transmission and storage; [making] makes them potential candidates for a wide range of IoT applications,” Hatton adds.
It should be noted that lensless smart sensor technology recently garnered significant attention from analysts, journalists and industry experts after Rambus officially kicked off its LSS POD program in Barcelona, Spain during Mobile World Congress 2015. The POD program offers partners early access to LSS hardware along with optimized algorithms.
Interested in learning more about the technology behind Rambus lensless smart sensors? You can check out our LSS article archive here.




