Recently, Semiconductor Engineering interviewed Paul Kocher, president and chief scientist of the Rambus Cryptography Research division, about various security risks associated with the rapidly evolving Internet of Things (IoT).
Search Results for: iot
Checking boxes is not a panacea for IoT security
Recently, Semiconductor Engineering interviewed Paul Kocher, president and chief scientist of the Rambus Cryptography Research division, about various security risks associated with the rapidly evolving Internet of Things (IoT).
In part one of the interview, Kocher told the publication that the industry is still more concerned with making a chip work than securing it.
“[This] approach at some point has to change, but the question is how bad does it have to get before people really care,” he explained.
As Kocher notes in part two, numerous airline companies actively collaborated during the early days of aviation by asking the government to regulate critical safety issues.
“People were dying and it was keeping the public away from airplanes, so even if an airline was doing a good job these issues made everyone look bad,” he said. “There is a possibility that someday we’ll end up with connected devices being highly regulated. I dread that, but I don’t see any other long-term solution because [certain] marketing messages are completely uncorrelated to technical reality.”
More specifically, says Kocher, there are companies that will routinely “check a box” to expedite the process of launching a new product.
“They want the least intrusive, least comprehensive evaluation possible,” he continued. “And then there are companies that have been hacked that want to understand their risk and mitigate it. If you get check boxes without teeth behind the consequences, it doesn’t help. If you can get liability and skin in the game for companies that control the risk, it would be transformative.”
As Kocher points out, there are a number of secure (containment) solutions that are beginning to appear on the market, including NXP chips.
“What happens in your processor is going to be independent of another chip, so it’s going to be decoupled even if the processor fails,” he explained. “The Crypto Manager cores [built by the Rambus Cryptography Research division] function within a chip as a separate security perimeter.”
Kocher also emphasized that some of the most frightening security threats involve people with modest resources who hire someone like a college undergraduate to find a bug.
“If the attack unfolds very slowly you can deal with it. If it happens quickly, you have to respond with stronger defenses. [As such], we need to focus on defenses that are more reliable and durable,” he added.
“We already have mathematical defenses. Turning that into something that can stand up to a level of threat gets us part of the way there. Turning off an application that is behaving badly but doesn’t damage the hardware—that’s something you can handle through risk management later.”
Interested in learning more? You can check out previous Paul Kocher security interviews here.
Smart lighting evolves for the IoT
Writing for the San Francisco Chronicle, Benny Evangelista reports that once-mundane household devices – such as light bulbs – are being transformed into smart, customizable tools.
“There’s a nice symmetry in smart light bulbs blazing the trail for the Internet of Things (IoT),” he explains.
Smart lighting evolves for the IoT
Writing for the San Francisco Chronicle, Benny Evangelista reports that once-mundane household devices – such as light bulbs – are being transformed into smart, customizable tools.
“There’s a nice symmetry in smart light bulbs blazing the trail for the Internet of Things (IoT),” he explains.
“When electric wires first appeared in homes in the early 20th century, the sole purpose was electric light. But inventors soon found other ways to use that wiring, giving rise to electric appliances like irons and vacuum cleaners.”
According to Kendra De Berti, a director at Rambus, the lighting industry is evolving to meet the needs of a rapidly expanding Internet of Things.
“WiFi, Bluetooth and ZigBee capabilities are being integrated into next-gen lighting designs to provide connected functionality – with an eye on building the smart home of the future,” De Berti explains. “Interacting with IoT-friendly lighting is made easy, as users control their environment across multiple devices, including smartphones and tablets. “
Concurrently, DIY Maker-centric companies like littleBits have introduced smart home kits to add IoT functionality to appliances such as lamps and bulbs that lack connectivity.
“The littleBits team utilized the $249 kit to create a smart refrigerator, Internet-connected speakers, a smart lighting system, a remote pet feeder, a smart AC, an SMS doorbell answering machine, a wireless lamp and more,” writes PSFK’s Melanie Ehrenkranz.
“This kit provides the bits necessary to create a customized, connected home with existing décor, appliances and furniture.”
It should be noted that a recent report published by MarketsandMarkets estimates the smart lighting market will be worth approximately $56.05 billion by 2020.
“In industrial, commercial as well as residential applications, lighting consumes around 40% of total energy cost,” the report reads. “Governments, industrialists [and] stakeholders are focusing on reducing the energy utilization by substituting traditional lighting with advanced energy-efficient lighting devices and technologies.”
Interested in learning more? You can check out Rambus’ lighting portfolio here, the Rambus-powered Enviro A19 LED Dimmable Light Bulb on Amazon here and the littleBits Smart Kit here.
Securing the IoT starts at the core
Writing for NewElectronics, Ben Jun of the Cryptography Research division of Rambus says securing the Internet of Things (IoT) starts at the core.
“The risks associated with a rapidly growing IoT include privacy, unauthorized access, malicious control and denial of service,” he explains.
Securing the IoT starts at the core
Writing for NewElectronics, Ben Jun of the Cryptography Research division of Rambus says securing the Internet of Things (IoT) starts at the core.
“The risks associated with a rapidly growing IoT include privacy, unauthorized access, malicious control and denial of service,” he explains.
“[Multiple] companies are developing solutions to address a diverse set of security requirements across multiple platforms and chips. The most robust security approaches bake security into the initial design and manufacturing of a SoC.”
According to Jun, numerous deployment scenarios require that IoT devices be provisioned with credentials and keys before they leave the device vendor’s facility.
“In today’s systems, the process of key injection during fabrication and test operations could potentially expose vulnerable key data,” he continues.
“In addition, test and debug capabilities are often fully enabled on chips by default – a relatively common practice that inadvertently creates additional security challenges.”
To be sure, embracing a hardware-first strategy and implementing the necessary functionality on the SoC level is a key element of fully securing devices and platforms such as FPGAs, wearables, smartphones, tablets and intelligent appliances.
“Although many continue to take security for granted, the importance of adopting a hardware-based approach at the most basic core level cannot be overemphasized,” he concludes.
“Aside from ensuring fundamental chip security during manufacturing, embedding the right security IP core into a SoC can help manufacturers design devices, platforms and systems that remain secure throughout their respective lifecycles.”
Interested in learning more? The full text of “Outlook 2015: Securing the IoT starts at the core” can be read on NewElectronics here.





