All the latest quantum computer articles

See the latest stories on quantum computing from eeNews Europe
Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts

Thursday, September 29, 2016

So what is JEFF, exactly?

So what on earth is JEFF and the Bouncy Castle?

Turns out, JEFF's a file format that gets around many of the problems of using Java in real time embedded designs, especially for the Internet of Things (IoT). Developed around 2002, it brings everything into one file and optimises it for memory space. This means that it can run on any Java virtual machine (VM), and these have got a lot smaller in the intervening years.

It also means that embedded projects can use Java libraries and developers - and both of those have grown tremendously over the years. It also helps provide key security libraries such as Bouncy Castle to add more security to an IoT design. Bouncy Castle is a lightweight open source cryptography API that makes securing IoT devices easier.

Why is this being mentioned now though? Well, Wind River has developed a VM for its VxWorks real time operating system called the Micro Engine, and is using the JEFF format to entice developers over to Java: Wind River resurrects real time Java file format for the Internet of Things

When you tie that up with VxWorks' links to IBM's Watson supercompuer-based data analytics service in the cloud, it starts to look very interesting.

By Nick Flaherty www.flaherty.co.uk

Other stories: 
Top ten IoT passwords show users are at risk
Symantec identifies IoT security risks
Top three trends in industrial automation
IoT market heads for shakeout
VxWorks links to IBM's Watson with 'edge-to-cloud'...
Moving IoT analytics to the network edge
PTC bids for IoT with ThingWorx
Synopsys launches ARC core to protect against IoT threats ...

Thursday, August 11, 2016

Vital end-to-end encryption for embedded IoT applications uses Amazon

By Nick Flaherty www.flaherty.co.uk

Securing the Internet of Things is a key challenge that is vexing many designers.Developing a secure end-to-end solution all the way to the cloud can be extremely challenging with lots of different hardware and software involved. Often the IoT node developers leave this for the gateway, leaving the end points vulnerable.

This is why the Embedded Blog has focussed not only on the hardware and software of the embedded node, but the links up to, and through, the cloud such as crypto accelerator cards - Kalray Launches Krypto128 Accelerator Card. So Microchip's launch of an end-to-end security IoT module that connects directly to Amazon Web Services IoT (AWS IoT) is highly significant.
Microchip used its acquisition of Atmel to work with AWS to use the AWS mutual authentication IoT security model. This should help companies to implement these security best practices from evaluation through to production. The solution adds a high level of security, simplifies the supply chain, and is now one of the fastest ways to connect to the AWS Cloud. 

Currently, third-party manufacturers of devices that connect to AWS IoT service must take specific actions to comply with the advanced security model. First, they must pre-register their security authority to AWS servers in order to establish a trust model. Second, for each IoT device they must generate unique cryptographic keys that are mathematically linked to the pre-registered security authority. Finally, the unique device keys must remain secret for the life of the device. In volume production, the generation and secure handling of these unique keys can be a daunting challenge in the chain of manufacturing especially where third-parties with different trust and compliance levels are involved.
All of this is a bit of a nightmare, to say the least, and one key reason why IoT security has been such a big issue.

Instead, the AT88CKECC development kit will allow customers to meet the security standard of AWS’ mutual authentication model and easily connect to the AWS IoT platform during the evaluation and engineering phase. Then the AWS-ECC508 device assists with meeting security standards during the prototyping and pre-production phase. Finally, devices will be customised for production stages to ensure information security in customer applications.

Customers simply solder the device on the board and connect it over I2C to the host microcontroller which runs an AWS Software Development Kit (SDK). Once this is complete, there is no need to load unique keys and certificates required for authentication during the manufacturing of the device as the AWS-ECC508 is pre-configured to be recognised by AWS without any intervention. All the information is contained in a small (3x2 mm), easy to deploy, crypto companion device.
The ECC508 device has strong resistance against environmental and physical tampering including countermeasures against expert intrusion attempts. In addition, the device features a high quality random number generator, the internal generation of secure unique keys and the ability to seamlessly accommodate various production flows in the most cost-effective manner. A typical IoT device consists of a small 8-bit microcontroller, and is battery powered. It is typically constrained for resources such as central processing unit (CPU) performance to provide low latency responsiveness, memory and code space for security protocols and for how much power they consume in order to preserve battery life. The ECC508 device has a low-power processor-agnostic cryptographic acceleration for compatibility with the widest range of resource-constrained IoT devices.

The AWS-ECC508 kit (AT88CKECC-AWS-XSTK, above) is available today priced at $249 each. The AWS-ECC508 (ATECC508A-MAHAW-S and ATECC508A-SSHAW-T) is available in UDFN and SOIC packages and is available today for sampling and volume production.

See www.atmel.com/tools/at88ckecc-aws-xstk.aspx for more information

Monday, February 22, 2016

Atmel moves IoT security into hardware

By Nick Flaherty www.flaherty.co.uk

Platform enables hardware crypto acceleration in IoT 

  • Supports OpenSSL and wolfSSL TLS implementations for hardware key protection and Secure Execution Environments
  • Accelerates core cryptographic processes with Co-Processor in  IoT Edge Nodes Applications
  • Pre-loaded with Unique Keys and Certificates to Reduce Complexities in Manufacturer Supply Chains


Atmel, currently being acquired by MIcrochip, has launched the industry’s first hardware interface library for TLS stacks used in Internet of Things (IoT) edge node applications. 
Hardening is a method used for reducing security risks to a system by applying additional hardware security layers and eliminating vulnerable software. Atmel’s new Hardware-TLS (HW-TLS) platform provides an API that allows TLS packages to use hardware key storage and cryptographic acceleration even in small, resource constrained edge node designs. HW-TLS is pre-loaded with unique keys and certificates designed to reduce the complexities of generating secure keys in the manufacturing supply chain.
TLS protocol stack
TLS protocol stack (Photo credit: Wikipedia)
OpenSSL is a general-purpose cryptography library that provides an open-source implementation of the Secure Sockets Layer (SSL) and TLS protocols. wolfSSL is a cryptography library that provides lightweight, portable security solutions with a focus on speed and size. The ATECC508A-OpenSSL and ATECC508A-wolfSSL libraries are available for immediate download at their respective software distribution repositories to provide more secure elements without disruption to the developer workflow.  
Secure hardening for both OpenSSL and wolfSSL is made possible with HW-TLS which allows those TLS software packages to interface seamlessly with Atmel's ATECC508A CryptoAuthentication co-processor. The ATECC508A provides protected key storage as well as hardware acceleration of Elliptic Curve Cryptography (ECC) cipher suites including mutual authentication (ECDSA) and Diffie-Hellman key agreement (ECDH). As such, HW-TLS allows developers to substantially harden Transport Layer Security (TLS), enhancing security for IoT-device and cloud-service ecosystems.
When used together, HW-TLS and the ATECC508A allow small, low-cost IoT nodes to implement strong cryptographic security. All private keys, certificates and other sensitive security data used for authentication are stored in secure hardware and protected against software, hardware and back-door attacks. In addition, the integrated ECC accelerators in the ATECC508A offload cryptographic code and math from the MCU allowing even a low end processor to perform strong authentication.
“Everyone with an interest in IoT security should be excited about Atmel HW-TLS with wolfSSL,” said Larry Stefonic, CEO, wolfSSL. “The combination of our secure software and Atmel’s new chips brings TLS performance and security to a level unrivaled in the industry. Atmel’s HW-TLS platform also makes it easier than ever for developers to incorporate truly hardened security into our TLS stack.”
With the rise of the IoT, security has become a pressing topic because autonomous remote devices are now routinely connecting to wireless networks to form complex smart-device and cloud-service ecosystems. As a result, autonomous smart IoT devices constitute a significant part of those networks and must be able to authenticate themselves to the network resources to maintain the integrity of the ecosystem. In addition, these remote, resource-constrained clients must be able to perform this authentication using minimal processing, memory and power.
Traditionally, TLS performed authentication and stored private keys in software. The Atmel Hardware-TLS platform closes the vulnerability gap in this arrangement by offloading the crucial key management responsibility to dedicated, tamper-resistant secure elements such as the ATECCC508A CryptoAuthentication device. In addition, the intensive crypto algorithms are processed in the CryptoAuthentication device, offloading the MCU on the remote devices and enabling the IoT edge node to authenticate to the cloud without a user-perceptible delay.Furthermore, Atmel Hardware-TLS comes as a complete platform pre-loaded with unique keys and certificates for eliminating the complexities of adding secure keys to each device in a manufacturing supply chain.
“With more and more remote devices being connected to the cloud every day in the era of the IoT, it becomes increasingly critical to ensure these devices are not vulnerable to attack,” said Nicolas Schieli, Sr. Director, Secure Products Group, Atmel. “Such devices can be entirely secure only when they are hardware secure, meaning the ‘secret’ keys are stored in a separate hardware unit. We are excited to bring this innovation to market, enabling device manufacturers that need to connect to the cloud to take advantage of hardware security.”
The Atmel Hardware-TLS platform complements Atmel Certified-ID, a seamless and secure keys provisioning platform for creating trusted Internet identities for smart connected devices.

Availability

Monday, January 04, 2016

ST teams with ClevX for wireless security for IoT

By Nick Flaherty www.flaherty.co.uk

Claim World’s First Wireless User-Authentication Technology Platform for IoT-Device Security
STMicroelectronics has teamed up with US encrypted flash-drive supplier ClevX to allow encrypted portable storage that is accessed with Bluetooth Smart wireless user authentication.
This means users can interact with secure portable storage (full-disk, XTS-AES 256-bit encryption) from their smartphones or wearable devices where all user data on the drive is encrypted and can be locked/unlocked using single- or multi-factor authentication. The technology is ideally suited for consumer and industrial applications such as healthcare, home automation and security, secure-access control systems, and portable data storage by providing a secure central repository for data.
“IoT-device authentication has long required trade-offs among security, convenience and mobility. The ClevX DataLock BT-secured portable storage provides the capability to actually enjoy the best of all worlds,” said Luca Difalco, VP of Marketing at STMicroelectronics’ Americas Region. “While we’re demonstrating the capability in an easy-to-use hardware-encrypted secure USB-Drive, the elegance and versatility of the solution is provided by an application that we can add to our BlueNRG device to make lock-down security accessible via Bluetooth Smart.”
ST and ClevX have reference designs for secure portable storage media, including Flash, hard-disk, and solid-state disk drives. These designs use ST’s BlueNRG Bluetooth Smart chips and ARM Cortex-M0+-based STM32L0 microcontroller that includes an AES encryption engine.The designs and software are immediately available for licensing and partnerships, including both ST/ClevX-based hardware and firmware in addition to the related smartphone and wearables apps.

The ST/ClevX reference designs are OS-host agnostic. USB drives with the DataLock BT technology operate across all computer platforms and embedded systems while providing various easy-to-use security layers (including a wireless lock/unlock mechanism, phone as an authentication factor, phone + PIN, or phone + PIN + userID/location/time). The reference designs support USB Remote Management, which can be critical for corporate deployments and remote password resets, drive disabling and erasing, and successful implementation of corporate-wide policies. 
“With the sensitive personal and corporate information that people carry on their USB drives, loss can easily lead to substantial financial penalties and undesired public disclosure,” said Lev Bolotin, Founder and CEO of ClevX. “Using ST and ClevX technologies, the DataLock BT Security solution protects data on a USB. Consumers, healthcare workers, mobile professionals, and corporations can improve their productivity and security on-the-go by using their phones to authenticate themselves to their USB drives and change security options, as required.”
Founded in 2005, ClevX is a Seattle-based IP/Technology development and licensing company with a secure, portable USB storage platform that is OS-agnostic, hardware-encrypted and bootable, as well as FIPS 140-2 Level 3 Certified devices and portable software applications.