Junko Yoshida of the EE Times reports that Rambus is diving into the field of cyber-security for OTA vehicle updates, which she describes as a “red-hot” issue for the current automotive market. “Rambus, a semiconductor and IP licensing company, has partnered with Movimento, a leader in automotive reflash services with innovations in OTA software,” Yoshida writes. “Combining Movimento’s OTA technology with Rambus’ own CryptoManager platform, the two companies have developed a system that offers one-time, single-use keys unique to each vehicle, ensuring validity before installation.”
Search Results for: cryptomanager
Rambus and Movimento secure OTA updates for connected vehicles
Rambus and Movimento have teamed up to deliver secure and personalized OTA updates for connected vehicles.
As Dr. Simon Blake-Wilson, VP of Products and Marketing at Rambus Cryptography Research points out, numerous OTA solutions designed to deliver functional updates and security patches use the very same software encryption key for multiple vehicles. Essentially, this increases the vulnerability vector of an update.

In contrast, updates provided by Movimento and Rambus are delivered via one-time, single-use keys that are unique to each vehicle – effectively minimizing vulnerabilities and maximizing security. More specifically, Movimento’s OTA technology uses CryptoManager to enable in-field provisioning of encrypted keys generated for a specific vehicle, thereby facilitating secure communication between cars and the Cloud.
“CryptoManager offers an integrated security platform with flexible implementation, comprising a hardware root-of-trust and secure firmware,” Blake-Wilson explained. “When combined with Movimento’s OTA technology, CryptoManager enables the next level of integrated chip-to-Cloud-to-car security. Simply put, CryptoManager is an embedded hardware solution that minimizes the attack surface of the vehicle by providing end point security,” Blake-Wilson concluded.
Movimento CTO Mahbubul Alam expressed similar sentiments.
“As cars continue to increase in complexity and connectivity, often depending on more than 100 million lines of code to function, car makers and consumers alike are demanding simple and secure methods to download, authenticate and install vehicle updates,” said Alam. “By partnering with Rambus and integrating the CryptoManager security platform with Movimento’s OTA solutions, we are able to further our strategy of building a best-in-class ecosystem of integrated solutions to enable the software defined car and data analytics.”
Interested in learning more? Movimento and Rambus are slated to demonstrate their joint security solution at TU-Automotive (Detroit) in booth C67. In addition, the official Rambus CryptoManager product can be viewed here, while an extensive article archive covering the security platform is available here.
Rambus and Movimento Team to Deliver Personalized Security for Automotive
Integrated solution provides highly secure over-the-air vehicle updates
TU-Automotive, Detroit – June 6, 2016 – Rambus Inc. (NASDAQ:RMBS), a leader in digital security dedicated to providing a secure foundation for a connected world, and Movimento, the leader in Over-the-Air (OTA) software lifecycle and data management for the automotive/IoT sectors, have partnered to deliver secure, convenient and personalized OTA vehicle updates critical to safety and performance in the era of the connected car.
The CryptoManager platform adds an important layer of security to the Movimento OTA solution. Vehicle updates provided by the combined Movimento and Rambus solution offers one-time, single-use keys that are unique to each vehicle, minimizing vulnerabilities and maximizing security. As part of the collaboration, Movimento’s OTA technology utilizes the Rambus CryptoManager platform, enabling in-field provisioning of encrypted keys generated for each vehicle and allowing for secure communication between a vehicle and the cloud.
“As cars continue to increase in complexity and connectivity, often depending on more than 100 million lines of code to function, car makers and consumers alike are demanding simple and secure methods to download, authenticate and install vehicle updates,” said Mahbubul Alam, CTO of Movimento. “By partnering with Rambus and integrating the CryptoManager security platform with Movimento’s OTA solutions, we are able to further our strategy of building a best-in-class ecosystem of integrated solutions to enable the software defined car and data analytics.”
Movimento’s tools and technologies are designed to reduce complexity when making software and firmware updates by updating all the ECUs in a car in one go securely. From the chip to the cloud, Movimento builds on more than a decade of experience in automotive industry with the company updating more than three million vehicles every year.
“Many current OTA solutions deliver functional updates and security patches for vehicles using the same software encryption key for multiple vehicles, increasing the vulnerability of the update,” said Dr. Martin Scott, general manager of the Rambus Cryptography Research Division. “The Rambus CryptoManager solution provides an integrated security platform with flexible implementation from the hardware root-of-trust to the secure firmware which, when combined with Movimento’s OTA technology, enables the next level of integrated chip-to-cloud-to-car security.”
The CryptoManager platform allows for cost reduction by enabling security features already embedded in automotive chipsets and requires no additional security hardware. By utilizing an embedded hardware solution, the CryptoManager platform minimizes the attack surface of the vehicle by providing end point security.
Movimento and Rambus will be demonstrating the joint solution at TU-Automotive in Detroit. Visitors can see how the solution works on a live demo using a Dodge RAM truck in the Movimento’s booth C67.
About Movimento Group
Devoted to developing advanced technologies that help realize The Software-Defined Car™, Movimento Group utilizes its decade long history as a leader in automotive reflash services and its innovations in OTA software. The company’s car manufacturer customers include Ford, GM, FCA and Volvo plus a wide range of Tier-1 suppliers including ZF, Bosch, Denso, Panasonic, Continental, Delphi, Visteon, Magna and others. The company’s headquarter is in Plymouth, Michigan, with offices in the Silicon Valley, Mexico, Sweden, Germany and Asia Pacific. For more information, go to www.movimentogroup.com.
About Rambus Cryptography Research
The Rambus Cryptography Research division is dedicated to providing a secure foundation for a connected world. Our innovative technologies span areas including tamper resistance, content and media protection, network security, and secure payment and transaction services. These technologies protect nearly nine billion licensed products annually, providing secure access to data and creating invaluable trust between our customers and their customer base. Additional information is available at rambus.com/security
About Rambus Inc.
Rambus creates cutting-edge semiconductor and IP products, spanning memory and interfaces to security, smart sensors and lighting. Our chips, customizable IP cores, architecture licenses, tools, services, training and innovations improve the competitive advantage of our customers. We collaborate with the industry, partnering with leading ASIC and SoC designers, foundries, IP developers, EDA companies and validation labs. Our products are integrated into tens of billions of devices and systems, powering and securing diverse applications, including Big Data, Internet of Things (IoT), mobile, consumer and media platforms. At Rambus, we are makers of better. For more information, visit rambus.com
###
RMBSTN
Press contacts:
For Movimento
Aoife Kimber
650-773-7288
[email protected]
From Racepoint Global for Rambus Inc.
Hilary Costa
(415) 694-6705
[email protected]
Automotive
Shifting gears for the IoT
Writing for Semiconductor Engineering, Ann Steffora Mutschler observes that a shift is currently underway in the automotive industry as more connected vehicles hit the road each year.
“[Connectivity adds] many of the features that consumers now expect in mobile devices as well as some new ones that ultimately will lead to autonomous vehicles,” she explained.

“But along with those changes are some nagging questions about just how safe [this] technology will be for consumers and others around them, and whether the whole system can be secured.”
As Mutschler acknowledges, such questions have been asked ever since the introduction of infotainment systems in cars.
“[However], the volume is increasing as more critical systems are connected to in-car networks and as more wireless features are added into vehicles,” she noted. “In effect, every new car is now an IoT device, and like every connected device, there are benefits and risks. But in the case of a two-ton object moving at high speed down a crowded highway, the risks are much more serious.”
According to Simon Blake-Wilson, VP of products and marketing for Rambus’ Cryptography Research Division, the industry is currently struggling with the concept of designing secure vehicles.
“We struggle in the sense that if you think about the security you apply to a mobile phone, it’s not like there is a magic bullet solution for mobile phone security. Similarly, everything about this from an [automotive] perspective must take into account many different security aspects,” Blake-Wilson told Semiconductor Engineering. “[Moreover], we struggle with the idea of whole-vehicle security just in the sense that people often come away expecting a magic bullet that’s going to solve the problem. We see cars being like other Internet connected objects, except much worse.”
As Mutschler points out, silicon foundries are now placing encryption algorithms into silicon with various technologies, including Rambus CryptoManager. Essentially, the CryptoManager platform acts as a foundational component capable of powering multiple security solutions. According to Blake-Wilson, a root of trust is the goal with any hardware-based security technology.
“For example, when you provision over-the-air updates, typically you sign those updates using a cryptographic mechanism called a digital signature scheme, with a private key and a public key. You sign the update with the private key, and the person that checks the signature has to have the right public key to verify it,” he continued. “A hardware root of trust manages the keys that you need to have, securing then in the right place to power the different security solutions. Once the key is in the right place, you go to the next step and use the key to check the signature. In the same way, you could use a hardware root of trust to provision keys and secure communications across the vehicle CAN [controller area network] bus as well.”
Including a root of trust in automotive semiconductors, says Blake-Wilson, will mark a critical security milestone for the industry.
“There will be a number of different applications or services that [require] security [measures]. Putting the right foundational capabilities into the chips that can be used by a variety of different applications will be key,” he concluded.
Interested in learning more about the Rambus CryptoManager platform? You can check out the CryptoManager product page here.
There is no giant Faraday cage for the IoT
A Faraday cage or Faraday shield can best be defined as an enclosure formed by conductive material that is used to block electric fields. As such, Faraday cages either heavily attenuate or block the reception and transmission of radio waves, which are a form of electromagnetic radiation.

Image Credit: Frank Vincentz (Via Wikipedia)
Unfortunately, there is no Faraday cage large enough to shield the burgeoning Internet of Things and related infrastructure from certain hacks such as simple power analysis (SPA) and differential power analysis (DPA). To be sure, all physical electronic systems routinely leak information about their internal process of computing. In practical terms, this means attackers can exploit various side-channel techniques to gather data and extract secret cryptographic keys from IoT endpoints.

“Regardless of specific instruction set architecture (ISA), most industry security solutions on the market today can be soundly defeated by side-channel attacks,” said Simon Blake-Wilson, a VP at Rambus’ Cryptography Research Division. “In fact, even a simple radio is capable of gathering side-channel information by eavesdropping on frequencies emitted by electronic devices. In some cases, secret keys can be recovered from a single transaction clandestinely performed by a device several feet away.”
The burgeoning IoT already comprises millions, if not billions, of connected endpoints powered by chips that are vulnerable to side-channel attacks. Such unprotected silicon (e.g., CPUs, MCUs, MPUs) can be found in a wide range of electronic devices including wearables, medical equipment, vehicles, smart appliances and rapidly evolving smart city infrastructure.
Perhaps not surprisingly, vulnerable Field Programmable Gate Arrays (FPGAs) are also gaining traction among IoT device manufacturers. Pankaj Rohatgi, a Security Technology Fellow at Rambus’ Cryptography Research Division, says the advantages of FPGAs include reduced time-to-market, field-configurability and lower up-front costs.
[youtube https://www.youtube.com/watch?v=l5Oi9xNR60s]
“FPGAs are increasingly being relied upon to protect highly-sensitive intellectual property, trade-secrets, algorithms and cryptographic keys. They are also a natural fit for certain elements of the IoT,” he explained. “Sensitive FPGA applications – such as power grids, medical devices and semi-autonomous vehicle infrastructure – all require strong tamper resistance to protect both the secrets contained within these devices as well as the data they process.”
As Rohatgi confirms, power analysis attacks are among the most important to protect against, since they are non-invasive, widely understood by adversaries and easy to execute via inexpensive off-the-shelf equipment.
“Fortunately, specific DPA countermeasure strategies can be employed to protect FPGA-based IoT devices and related infrastructure,” he said. “These include techniques to minimize information leakage, generating noise to drown out leakage signals, the use of randomness to mask computational intermediates, algorithm and implementation obfuscation as well as the use of protocols designed to preserve secrecy even in the presence of (some) leakage.”
However, as Blake-Wilson emphasizes, side-channel attacks are only one specific attack vector threatening the IoT.

“The current security paradigm associated with the mobile and PC world is undeniably flawed. I find it difficult to believe that any serious industry player is honestly satisfied with the status quo, in which serious or even critical vulnerabilities disclosed on an almost daily basis are patched with hurriedly coded software and firmware updates,” he concluded. “A ‘good enough’ approach may have been tolerated for smartphones and tablets, but the industry cannot afford to relegate security to a tertiary concern for an IoT that may very well ultimately affect every aspect of our daily lives. A new paradigm, designed from the ground up to provide secure foundations for connected devices, is clearly long overdue. Devices need to be secured throughout their lifecycle from chip manufacture, to day-to-day deployment, to decommissioning. Alongside side channel attacks, secure provisioning and configuration are crucial issues that we are addressing with CryptoManager.”





