Many of the things we use on a daily basis are becoming smart and connected to the Internet. The Internet of Things (IoT) will improve our lives by helping us reach our health and fitness goals, reduce resource consumption, increase productivity, and track and secure our assets. Many embedded developers realise the potential benefits of the IoT and are actively developing various applications, from connected home devices to wearables and home security systems. However, along with these benefits come risks. No one wants to design an application thats prone to hacking or data theft. Undesirable events like high-profile hacks can lead to serious damage to brand images and loss of customer trust, and, in the worst cases, slow down or permanently reduce the adoption of the IoT.
The IoT is often referred to as an industrial revolution. The number of connected devices will grow rapidly in the coming years. If there is any disagreement among analysts who follow the IoT, it is in the number of billions of devices that will be connected. The economic value to society is estimated to be in the range of $4-11 trillion dollars.
In the race to accelerate time-to-market for connected device products, implementing proper security is inconvenient because it adds component cost, development effort and design complexity. At the same time, in some industries, it is not crucial to have adequate security. Rather, having adequate security is a key to not being hacked. Major security and privacy issues and bad press after a vendors product has been hacked might temporarily or permanently slow down the adoption of IoT. Many consumers are already skeptical about connecting even simple devices in our homes and daily lives, and some researchers and industry watchers believe the IoT is a security catastrophe waiting to happen. In fact, quite recently, there have been a number of highly publicised hacks that are gaining wide attention so one could argue that the catastrophe is already on its way.
Hacking of quantum cryptography
The current IoT security situation resembles that of quantum cryptography, often referred to as quantum key distribution. Unlike other key distribution schemes, quantum cryptography promises unconditional security based on the laws of physics. In comparison, most key distribution schemes rely on assumptions of the computational complexity of factoring large numbers or the discrete logarithm problem.
Although quantum cryptography was discovered in 1984, it took until the year 2000 before commercial cryptography systems were brought to market. Relying on single photons, a quantum cryptographic system is complicated to build, and yet time-to-market is of the essence. In 2010, the first security loophole that completely broke the security of these quantum cryptography systems was published. Quantum cryptography is, theoretically, impossible to break, but, in reality, side-channels, or loopholes, were not considered during system design. Also, interestingly, no loopholes were discovered until a dedicated team was assembled to break into such systems. Up until the time this team was established, the entire industry was focused on making quantum cryptography systems robust and getting them to market.
The quantum cryptography analogy teaches us important lessons. Most notably, it shows how security is an ongoing process requiring a multidisciplinary approach to anticipate potential hacks. When striving to make something as complex as a quantum cryptographic system work, the same engineering team cannot possibly be able to understand how an attacker could break into the system. These are conflicting thought processes. Thus, a quality assurance and security team needs to be separate from the engineering team building secure systems.
Another key point is that the hacking of the quantum cryptography system surely has temporarily, if not permanently, reduced market acceptance of and belief in this technology. Thus, it would probably have been beneficial for the industry to invest more in security up-front, leading to a longer time-to-market and greater cost but also substantial gain in the end.
Anatomy of a secure IoT thing
The technology necessary to make the IoT secure already exists. But the lack of knowledge of how to implement this technology is usually the root cause of most security loopholes. A secure Internet-connected thing does not, however, guarantee a secure system. Nevertheless, developers should at least be aware of the following types of security.
Hardware-level security
The secure IoT-device has a number of security features. First and foremost, it uses asymmetric cryptography to perform secure boot and secure boot loading or over-the-air (OTA) firmware updates. The secure IoT-device also uses hardware cryptographic accelerators that are faster, more energy efficient and less vulnerable to side-channel analysis.
In a secure IoT device, the debug port is closed. If it is necessary at some point to reopen the debug port (in the case of a remote memory access or for other reasons), this is accomplished by an authenticated challenge response scheme using public key authentication.
While secure boot and boot loading prevent adversaries from modifying the program memory, the secure IoT device further restricts access to reading the program memory. This means devices that feature internal memory or on-board flash. In the case of external memory, it also means that the contents of the external memory are signed and encrypted.
Software security considerations
To ensure that the software running on the secure IoT device further enhances security, it must be hardened in critical sections. This means that it can resist skipping single instructions. Examples include the secure boot signature check or a password signature check. This approach ensures that if an adversary is able to make the processor skip an instruction, it does not have security-critical consequences. Furthermore, to avoid security issues in the code or a third-party library causing system-wide access, TrustZone for ARM v8M can be used to compartmentalise the various libraries.
Secure communications
Most integrated circuits communicate with other ICs, other IoT-devices, gateways and/or the cloud, and it is necessary to secure these communication channels. When communicating with other ICs, it means turning on encryption and authentication to ensure integrity and confidentiality. One example could be storing data on off-chip memory or the wired bus between sensors or communication ICs and the main processor.
When communicating with other IoT-devices, communication protocols such as ZigBee, Thread or Bluetooth low energy are typically used. Most of these protocols have security options, and it is important to turn on these security options.
Another important consideration is device commissioning. Once secrets have been deployed between the communicating devices, securing data traffic is straightforward. However, it is not straightforward to distribute the secrets. For wireless devices, this typically involves the commissioning step in which the device is brought on to the wireless network, e.g., using Bluetooth to commission a connected light bulb to a ZigBee-based lighting mesh network. The options for commissioning depend on the systems general capabilities, as well as a trade-off between ease-of-use and security. Suffice it to say that the secure IoT-device does not compromise security. In addition, the secure IoT-device uses TLS/DTLS to establish secure end-to-end connections to the cloud.
Application layer
The application layer might be on the device, in the cloud service or a combination of the two. In many applications, it is necessary to have password protection, typically in the application layer. The secure IoT-device forces the user to change the password and blacklists the most frequently used passwords. If possible, the device can even enforce two-factor authentication.
System considerations
From a system point of view, a number of seemingly harmless subsystems can add up to an insecure system as a whole. Therefore, to make a secure IoT-device, there are few assumptions for implementing security within each subsystem. Each subsystems security is independent or minimally dependent upon the other subsystems security.
It is necessary for developers, device makers and service providers involved in the IoT ecosystem to accept the costs and time-to-market delays of implementing effective security at all levels within the IoT, from device to cloud, and from the beginning of each development effort. Concerted efforts to implement security throughout the IoT will help prevent devastating security loopholes, resulting bad press, and a market that might not want to invest in IoT even when the loopholes have been closed.
Lars Lydersen, director of product security, Silicon Labs,was a part of the team that broke into unbreakable commercial quantum cryptographic systems. Currently, he has shifted his focus to classical embedded security systems and works at Silicon Labs in Oslo, Norway. Lydersen holds an MsC in electronics and a PhD in quantum cryptography from the Norwegian University of Science and Technology.
Go here to see the original:
Anatomy of a secure internet-connected thing - Electronics Weekly - Electronics Weekly
- Cardiac Anatomy & Orientation of the 3D Heart Part 3 - University of Nebraska Medical Center - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy Star Chris Carmack Teases Link and Jos Season 22 Storyline: Anything Can Happen - Life & Style - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy Star Reveals Her Secret to Flying Under the Radar on Planes - EntertainmentNow - June 1st, 2025 [June 1st, 2025]
- None of her preserved anatomy looked like any other fossil. Scientists Realize That A Fossil Thats Millions Of Years Old Was Fossilized From The... - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy star is fighting to get Denzel Washington on the show: 'Im hoping he does it' - GeekSided - June 1st, 2025 [June 1st, 2025]
- No, Sandra Oh is not watching Greys Anatomy in her free time - GeekSided - June 1st, 2025 [June 1st, 2025]
- Brigitte and Emmanuel Macron the anatomy of a slap - The Spectator World - June 1st, 2025 [June 1st, 2025]
- Sandra Oh Reveals If She Watches Grey's Anatomy Reruns 11 Years Since Cristina Yang Left The Show - Screen Rant - June 1st, 2025 [June 1st, 2025]
- Fan-Favorite Greys Anatomy Star Sandra Oh Reveals Whether She Still Watches the Show or Not - Collider - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy: Why Did Sandra Oh Leave The Show? Revisiting Her Shocking Exit & Remarkable Legacy - Koimoi - June 1st, 2025 [June 1st, 2025]
- Warfare at night, deepfakes by day: The anatomy of a rumour in modern era conflicts - The Indian Express - June 1st, 2025 [June 1st, 2025]
- Greys Anatomy Hunk, 59, Turns Heads in Rare Monaco Outing With Wife - parade.com - June 1st, 2025 [June 1st, 2025]
- Grey's Anatomy season 22 confirmed to premiere in fall 2025 - GeekSided - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy season 21 finale: Where to watch for free tonight - MassLive - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Showrunner Meg Marinis Confirms Your Fears After That Explosive Cliffhanger Finale - The Hollywood Reporter - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' Recap: Did Firebomb Just Kill Off Lucas Adams, Teddy Altman, or Miranda Bailey? - TV Insider - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy season 22 will not introduce any major new additions: 'I have a big enough cast as it is' - GeekSided - May 21st, 2025 [May 21st, 2025]
- 8 Biggest Unanswered Questions & Mysteries After The Grey's Anatomy Season 21 Finale - Screen Rant - May 21st, 2025 [May 21st, 2025]
- Only 2 Grey's Anatomy characters are confirmed to be safe in season 22 - GeekSided - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy': Meredith Puts Herself in Harm's Way Once Again as a Hostage Situation Leaves Grey Sloan Reeling - People.com - May 21st, 2025 [May 21st, 2025]
- This Greys Anatomy character death still remains the shows most gut-wrenching - GeekSided - May 21st, 2025 [May 21st, 2025]
- Anatomy Of A Perfect Trip Cybercaf Across The Algarve - Quartersnacks - May 21st, 2025 [May 21st, 2025]
- Why the Greys Anatomy Hospital Is Facing Another Bomb Threat in Season 21 Finale - E! Online - May 21st, 2025 [May 21st, 2025]
- Streaming Set Another Record In April, But Greys Anatomy And The White Lotus Prove Linears Reach, Nielsen Says - Deadline - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' Boss Answers the Biggest Questions From That Explosive Season Finale (Exclusive) - parade.com - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Season-Finale Recap: Explosions in the Sky - Vulture - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Boss Breaks Down That Explosive Season 21 Finale Cliffhanger, Merediths Surprising Decision - TheWrap - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy boss confirms one new star will return in season 22 - GeekSided - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Season 21 Finale Review: I Cant Believe The Show Pulled Off This Cliffhanger Reminiscent Of Its Glory Days - Screen Rant - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy Finale Preview: Chris Carmack Teases 'Be Afraid' - Us Weekly - May 21st, 2025 [May 21st, 2025]
- ABC NEWS STUDIOS ANNOUNCES HEY BEAUTIFUL: ANATOMY OF A ROMANCE SCAM BEGINS STREAMING MAY 20, ONLY ON HULU - dgepress.com - May 21st, 2025 [May 21st, 2025]
- 5 Grey's Anatomy characters who might not return for season 22 after that fiery cliffhanger - GeekSided - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Explosion & Possible Character Deaths: Showrunner Explains Why Shes Doing This to Link & Jo - Just Jared - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' season 21 ending explained: Is Meredith returning to Grey Sloan for good? - Entertainment Weekly - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy Season 21 Finally Resolved Its Most Frustrating Plot In Limbo - Screen Rant - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy Season 21 Ending Explained: Amelia Survives A Near-Death Experience While Tragedy Strikes A Fan-Favorite - Screen Rant - May 21st, 2025 [May 21st, 2025]
- James Pickens Jr. Says Every Day Is an Adventure on 'Greys Anatomy' (Exclusive) - People.com - May 21st, 2025 [May 21st, 2025]
- The Doctor Is Out: Greys Anatomy Ends Season 21 With a Devastating Death - Yahoo - May 21st, 2025 [May 21st, 2025]
- Greys Anatomy Season 22 Cast: Only 2 Characters Confirmed Alive After Finale, Though 7 More Actors Have Deals to Return - Just Jared - May 21st, 2025 [May 21st, 2025]
- 'Grey's Anatomy' Interview: James Pickens Jr. Reflects on Pilot and Reveals Season 22 Hopes (Exclusive) - TV Insider - May 21st, 2025 [May 21st, 2025]
- Grey's Anatomy tells fans to "brace yourself" for season finale that's as dramatic as this iconic episode - Digital Spy - May 21st, 2025 [May 21st, 2025]
- I Can't Believe Grey's Anatomy Still Hasn't Told Us Who Adams' Mother Is - Cinemablend - May 21st, 2025 [May 21st, 2025]
- Katherine Heigl Shares Why She's Grateful Her Daughters Aren't Interested in Grey's Anatomy (Exclusive) - parade.com - May 12th, 2025 [May 12th, 2025]
- 'Grey's Anatomy' Fans Are Just Realizing This Fun Fact About the Series That Affects All but 1 Episode - People.com - May 12th, 2025 [May 12th, 2025]
- In a Nutshell: Turning anatomy education into online sensation - Ohio University - May 12th, 2025 [May 12th, 2025]
- 'Grey's Anatomy' Gets Musical Again: Link Serenades Jo With Song at the Wedding Altar - TV Insider - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Boss Unpacks Jo and Links Momentous Wedding Song, Teases Bonkers Season 21 Finale - TheWrap - May 12th, 2025 [May 12th, 2025]
- Generating cervical anatomy labels using a deep ensemble multi-class segmentation model applied to transvaginal ultrasound images - Nature - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy creator Shonda Rhimes reveals the hardest death she had to write - Yahoo - May 12th, 2025 [May 12th, 2025]
- Katherine Heigl Reveals What 1 Medical Trick She Thinks She Could Still Do After Grey's Anatomy (Exclusive) - parade.com - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Season 21, Episode 17 Review: As A Long-Time Fan, I Loved This Romantic & Poignant Episode That Felt Like Classic Greys - Screen... - May 12th, 2025 [May 12th, 2025]
- As One Greys Anatomy Couple Weds, Another Breaks Up and a Third Relationship Lands on Life Support - TVLine - May 12th, 2025 [May 12th, 2025]
- Every Wedding on Greys Anatomy , Ranked - Vulture - May 12th, 2025 [May 12th, 2025]
- 'Greys Anatomy': Link Surprises Jo at Their Wedding, Owen Holds onto the Past and 1 Couple Calls It Quits - People.com - May 12th, 2025 [May 12th, 2025]
- Here comes the bride: Where to stream Greys Anatomy for FREE - PennLive.com - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Preview: Will Link and Jo I Do It Right On Their Wedding Day? Plus, [Spoiler]s Back - TVLine - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy boss reveals the disappointing reason Meredith missed Jo and Links wedding - GeekSided - May 12th, 2025 [May 12th, 2025]
- Anatomy Of Startup Governance Issues, Funding Zooms & More - StartupNews.fyi - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Shock: Lucas and Simone Split Will Fans Even Miss Them? - Decatur Metro - May 12th, 2025 [May 12th, 2025]
- 9 Secrets of the Greys Anatomy Sets Superfans Need to Know - Architectural Digest - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy Continues to Ignore a Key Character's Storyline (& It's Frustrating Fans) - Comic Book Resources - May 12th, 2025 [May 12th, 2025]
- Jo & Link's Unique Wedding Set-Up Is Exactly Why Their Romance Works In Grey's Anatomy - Screen Rant - May 12th, 2025 [May 12th, 2025]
- Greys Anatomy creator Shonda Rhimes reveals the hardest death she had to write - The Independent - May 12th, 2025 [May 12th, 2025]
- Grey's Anatomy fans are just realizing clever aspect of 'every episode' after 20 years - The Mirror US - May 12th, 2025 [May 12th, 2025]
- Did the Success of The Substance and Anatomy of a Fall Finally Teach Cannes a Lesson? - IndieWire - May 12th, 2025 [May 12th, 2025]
- Grey's Anatomy fans floored after spotting 'hidden message' in every episode - Irish Star - May 12th, 2025 [May 12th, 2025]
- Anatomy of an apprehension: Where are you taking the baby? - Maple Ridge-Pitt Meadows News - May 12th, 2025 [May 12th, 2025]
- Isaiah Washington Says Sandra Oh Brought Him Back on Greys Anatomy Years After Firing - E! Online - April 27th, 2025 [April 27th, 2025]
- Hailey Bieber Is Outed as an Obsessive 'Greys Anatomy' Fan: It's 'a Big Secret' - People.com - April 27th, 2025 [April 27th, 2025]
- Unfurling Anatomy explores neuroplasticity and healing through artistic expression - 13wham.com - April 27th, 2025 [April 27th, 2025]
- Why isnt Greys Anatomy on TV tonight? When is the next new episode? - PennLive.com - April 27th, 2025 [April 27th, 2025]
- Why Greys Anatomy Isnt Airing a New Episode Tonight (April 24) & When Itll Return - Just Jared - April 27th, 2025 [April 27th, 2025]
- Greys Anatomy season 21 new episode tonight - How to watch on ABC for free - MassLive - April 27th, 2025 [April 27th, 2025]
- Anatomy of a US Treasury Sell-Off - AllianceBernstein - Commentaries - Advisor Perspectives - April 27th, 2025 [April 27th, 2025]
- Anatomy Of Lies Documentary: Everything To Know About The Grey's Anatomy Writer Who Faked Cancer (& Where To Watch Online) - Screen Rant - April 27th, 2025 [April 27th, 2025]
- 'Greys Anatomy' Star Katherine Heigl Slammed With Lawsuit For Alleged $300,000 Unpaid Services - Yahoo - April 27th, 2025 [April 27th, 2025]
- Grey's Anatomy's Isaiah Washington Says Sandra Oh Brought Him Back After Altercation with Patrick Dempsey - E! Online - April 27th, 2025 [April 27th, 2025]
- Why Arent 9-1-1, Doctor Odyssey & Greys Anatomy New Tonight? - The Sanford Herald - April 27th, 2025 [April 27th, 2025]
- 'Grey's Anatomy' Teases a Winston/Jules Pairing: Are You Feeling It? - TVLine - April 27th, 2025 [April 27th, 2025]
- Anatomy of a PMs fall: did Albanese stumble off a stage - and why are we still talking about it? - The Guardian - April 27th, 2025 [April 27th, 2025]