Rambus has announced that its CryptoManager security platform now supports in-field feature and service provisioning, alongside SoC management and device personalization capabilities. “In-field feature and service provisioning enables complete silicon-to-cloud functionality to support the growing requirements of trusted applications,” said Dr. Martin Scott, senior VP and GM of the Rambus Cryptography Research division. “These include secure mobile banking, identity and entertainment, along with IoT device security.”
Search Results for: iot
Rambus lensless smart sensors go thermal
Rambus scientists have debuted thermal-enabled lensless smart sensor (LSS) technology at MWC 2016 in Barcelona. As Rambus Labs VP Gary Bronner notes, LSS now supports thermal capabilities alongside the visible spectrum. “LSS can enable a future where IoT technology is infused in every aspect of modern life, from smart cities and transportation to medical equipment and manufacturing,” said Bronner.
CryptoManager Trusted Provisioning Services
Secure Element in the Cloud
Is Mr. Robot the new WarGames?
WarGames – which hit theaters way back in 1983 – is an early hacker film starring Matthew Broderick (David Lightman) and Ally Sheedy (Jennifer Mack). For the uninitiated, WarGames depicts the fictional story of David Lightman, a high school hacker who unintentionally accesses WOPR, a military supercomputer operated by the U.S. Department of Defense (DoD).
Believing he is playing an unreleased computer game, Lightman and Mack run a nuclear war simulation (Global Thermonuclear War) on WOPR, prompting a missile scare and nearly kicking off World War III. Ultimately, WOPR realizes that nuclear war is a “a strange game,” in which “the only winning move is not to play.” Watched by none other than President Regan himself, WarGames offers a stark warning about the danger and futility of nuclear conflict between the United States and the Soviet Union.
[youtube https://www.youtube.com/watch?v=hbqMuvnx5MU]
As Wired’s Scott Brown points out, the Cold War-era WarGames has essentially “written itself” into the cult lore of Silicon Valley. Indeed, Google co-founder Sergey Brin told a packed 2008 symposium in Mountain View that WarGames was a key movie of a generation, “especially for those of us who got into computing.”
Fast forward to 2016. Although the Cold War is long over, the dark, post 9/11 NYC depicted in USA Network’s Mr. Robot is far from a secure utopia. To be sure, the star of the wildly popular series is Elliot Alderson (Rami Malek), a cyber-security engineer and vigilante hacker who suffers from social anxiety disorder, clinical depression and a morphine habit.
“We now live in a world where hacks of all kinds are happening with alarming frequency and data dumps have become a weapon in both the geopolitical and personal arenas,” writes Jenna Worthman of the New York Times. “Mr. Robot feels, then, like a fictional CliffsNotes for the dark corridors of the Web. Cyber-espionage and geopolitical sabotage via cyber-attack is more than a paranoid fantasy; it is the new normal.”
Robot, says Worthman, may be fictional, but at least the series “helps us make sense of the strange new world taking shape beneath our feet.”
[youtube https://www.youtube.com/watch?v=gEm7vgXt2M0]
Meanwhile, Emmanuel Goldstein, writing in the 2600 Hacker Quarterly, notes that like Eliot, most of us are essentially trying to get by and figure out what’s right and wrong.
“This is what Eliot Alderson struggles with throughout the story. He remains a true hacker regardless of the choice he makes and how he’s manipulated,” he opines. “Sure, he breaks the rules a few times and invades the privacy of those he’s interested in, as is the case with members of virtually every element of society. And as a hacker, he’s very good at what he does. But it’s all of us who make the world of lost privacy, powerful integrated/intelligent systems and poor security a reality.”
Indeed, Kor Adana, a writer for the hit series, recently told a cyber-security conference that Robot has synched up well with real life events. As we’ve previously discussed on Rambus Press, a number of Robot hacks have actually occurred in reality, ranging from compromised PLC devices to malware-packed USB sticks dropped in parking lots to tempt unsuspecting victims.
“The show gets people on a certain wavelength when they realize oh, my webcam really can be used to spy on me,” said Adana. “And maybe I shouldn’t just blindly accept a CD from a street peddler. [Robot] illustrates the very real risks for the average person. An increased level of paranoia is clearly a good thing in this landscape. It comes along with the territory, because we know how to exploit these vulnerabilities.”
Clearly, Robot is helping to raise awareness of cyber-security risks for a more mainstream audience. In this context, the series may very well be the WarGames of 2016, with both hackers and security companies paying close attention to each episode of the blockbuster show. The specter of nuclear war between two superpowers may have faded along with the 1980s, but as Robot illustrates, our world remains a fundamentally insecure dystopia.
Building silicon foundations for security
Paul Kocher, the chief scientist of Rambus’ Cryptography Research division, recently presented a DesignCon 2016 keynote session that explored the crowded intersection of hardware, Moore’s Law and cryptography. As Kocher notes, cryptographic limits have historically been constrained by a salient lack of computing power.
“[Following Moore’s Law], more computing power enables much stronger algorithms,” he explained. “[Concurrently], more robust computing power has also led to an increasing number of security breaches at all levels. In fact, within two years, approximately 90% of all IT networks will experience an IoT-based security breach.”
This trend of insecurity can only be expected to continue, says Kocher, with analysts forecasting some 50 billion connected devices by 2020.
“There will be more devices, more valuable data and more complexity. What does this mean for attackers? More targets, reward and vulnerabilities,” he continued. “[As such], it is important to realize that security is fundamentally different from functionality. The former requires very different engineering strategies and assumptions.”
Incorrect assumptions, warns Kocher, often leads to negative outcomes.
“One could falsely assume hardware and software logic will be bug free. However, the reality is that current devices are one to three exploits away from total breach, with overwhelming likelihood of vulnerabilities at each layer,” the chief scientist confirmed. “SoCs are usually just one bug away from ruining software protections.”
One such vulnerability highlighted by Kocher during the keynote session was side-channel attacks.
“The [typical] assumption is that attackers only see the binary input/output data. The reality? Power & RF measurements show tiny correlations to individual gates,” he explained. “The information content of a secret key is tiny (typically 128-2K bits). Information can be extracted from noisy channels. The attack [vector] is to measure, divide into subsets and compare subset average.”
According to Kocher, the price of maintaining the insecurity status quo is steadily increasing due to FTC actions, litigation, insurance costs and various regulatory risks. In contrast, hardware-based security offers manufacturers a number of benefits, including deterrence against physical theft, optimized inventory management (chips can be configured and re-configured) and a separate IPR license for global trade (with configuration codes generated after import).
“Robust security will eventually be required – often for many use cases, such as DRMs, payment schemes, credential systems and device keys. [Plus], falling transistor costs – as per Moore’s Law – means lower per-chip manufacturing cost for security features,” he explained. “Moreover, it is important to remember that [stand-alone] software security doesn’t scale and there is no hope of eliminating bugs in existing software. The situation is getting worse, not better, as patching is expensive and not very effective.”
Separate chips, says Kocher, can help, although designers should be aware of the associated impact on cost, performance, size and power draw. In addition, interfaces – between the security and other chips – can themselves be vulnerable.
“Secure ‘on-SoC’ logic blocks are better, as they are isolated from the main processor and all of its software by an intra-chip security perimeter. In short, they are more cost effective and offer better security,” Kocher explained.
“[This is precisely why] the Cryptography Research division of Rambus designed the CryptoManager core to protect and deliver keys and configuration settings for use throughout an SoC’s hardware and software [layers]. Meanwhile, the CryptoManager server (or service) delivers keys and authorizations to factories or data centers and audits usage.”
The current generation of hardware, Kocher concludes, provides a rather poor foundation for consumer security.
“It is built with incorrect assumptions about software quality. The technology industry’s impact depends on finding solutions. Otherwise, the lack of security will erase net benefits from new technology such as the IoT,” he added.










