This page was machine-translated and may differ from the original. View original

Microchip-TTI Launches End-to-End LoRa Security Solution

Google 우선 소스Published2019.02.09 09:01
| Dramatically Simplifies LoRaWAN Device Provisioning
| Preventing external exposure of sensitive keys during device deployment
| Full control of device keys without vendor lock-in


As the LoRa (Long Range) technology ecosystem expands, security remains an area of improvement in the market due to vulnerabilities that allow access to network and application server keys in memory modules and microcontrollers (MCUs) with LoRaWAN stacks built in.

If keys are accessed on a LoRaWAN device, hackers can steal them and use them to perform fraudulent transactions, potentially resulting in a catastrophic attack that could harm service revenue, incur recovery costs, and damage brand equity.

Microchip LoRa End-to-End Security Solution

Microchip Technology Inc. (NASDAQ: MCHP) today announced a partnership with The Things Industries (TTI) to launch the industry's first end-to-end security solution that adds secure, trusted and managed authentication to LoRaWAN devices on a global scale.

This solution integrates the agnostic ATECC608A-MAHTN-T CryptoAuthentication device, which can perform its functions regardless of any knowledge of MCU and radio, with TTI's managed join server and Combined with Microchip's secure provisioning service, it provides hardware-based security to the LoRa ecosystem.

This joint solution significantly simplifies LoRaWAN device provisioning and addresses the inherent transport challenges associated with managing LoRaWAN authentication keys throughout the device's lifecycle.

Because LoRaWAN devices are deployed in the field after passing through various supply chain stages, network and application server keys have traditionally not been protected and monitored at the edge node. The Common Criteria (CC) Joint Interpretation Library (JIL) “High” rated ATECC608A pre-configures secure key storage to keep a device’s LoRaWAN cryptographic keys separate from the system, preventing sensitive keys from being exposed externally during the supply chain or device deployment.

Microchip's fully secure manufacturing facilities securely supply keys, eliminating the risk of exposure during production. This solution, which incorporates TTI's agnostic secure join server service for LoRaWAN network and application server providers, reduces the risk of device identity compromise by establishing reliable authentication when devices connect to the network.

Similar to prepaid data plans for mobile phones, the purchase of the ATECC608A-MAHTN-T device includes one year of managed LoRaWAN join server service through TTI.

When a device identifies itself to join a LoRaWAN network, the network contacts the TTI join server to verify that the identity comes from a trusted device and not a tampered device. The temporary session key is securely transmitted to the selected network server and application server.

TTI's Join Server supports all LoRaWAN networks, from commercial networks to private networks built with open-source components. After the one-year service period, TTI offers an option to extend the service.

“Hardware-based security is essential for today’s connected applications,” said Nuri Dagdeviren, vice president of Microchip’s Secure Products Group. “Just as a Subscriber Identity Module (SIM) card securely stores a global mobile ID number and associated keys that authenticate subscribers in a mobile phone, the ATECC608A adds a hardware Root of Trust (RoT) to the LoRa ecosystem to establish trusted authentication when a device connects to the cloud.”

Microchip and The Technology Institute (TTI) have also been collaborating to ensure seamless and secure deployment of LoRaWAN devices. LoRaWAN device IDs are verified by the TTI Join Server with minimal intervention, relieving developers of the burden of security expertise required.

Customers can select any LoRaWAN network and even migrate to a different LoRaWAN join server by rekeying the device. This means customers have full control over where and how their device keys are stored, without vendor lock-in.

“The rapidly growing LoRaWAN market requires efficient and secure systems that reduce the time it takes to provision devices while providing additional security,” said Johan Stokking, CTO of TTI. “We are excited to be working with Microchip to enable security in devices leveraging the global network.”
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자