This page was machine-translated and may differ from the original. View original

Protecting IoT from Hackers? Hardware-Based Security Is Needed

Google 우선 소스Published2020.09.14 15:29
IoT devices are increasingly likely to become system attack vectors.
Hardware-based security, protecting your devices from hackers
Provides various authentication processes to protect



It was already proven in 2016 by researchers at the Weizmann Institute of Science in Israel and Dalhousie University in Canada that it was possible to hack into home and business networks using smart light bulbs.

Even recently, there have been cases of IoT devices without security patches being compromised by cyberattacks. Hackers have hijacked access control systems in smart doors or smart buildings, then launched DDoS attacks to gain access to internal networks.

While IoT devices bring significant convenience to our lives, if security is not thorough, they can become a gateway for hackers to infiltrate networks and access sensitive data. IoT devices must be protected against security threats, especially those prone to security breaches.

If smart medical devices like pacemakers are hacked, it could be potentially fatal for the user. Medical applications must ensure the authenticity of their internal sensors and protect the product from counterfeit products. The authenticity of the data collected by the sensor must be verified, and the number of times disposable or limited-use peripheral devices are used must also be thoroughly checked.
▲ Cryptographic coprocessors are used in pacemakers that can access the Internet.
Protecting Smart Medical Devices from Security Threats [Photo = Maxim]

Another area where security is crucial is the industrial IoT. An attack on automated factory equipment can disrupt production lines and even lead to lost revenue. In this area, it's crucial to verify the authenticity of OEM modules and establish point-to-point security.

Functional control is also important. In manufacturing, supporting multiple versions and stages of functionality on a single board is cost-effective. Ensuring that secure end users can perform feature upgrades also protects the integrity of these upgrades.

Key challenges to addressing IoT design security include: ▲safety and reliability to prevent the use of counterfeit components that could pose a risk to customer safety; and ▲key management to protect and encrypt sensitive data with vulnerable security systems.

And there are ▲secure boot against unauthorized firmware that can be an opportunity for malware attacks ▲endpoint security ▲function controls to safely enable and disable various factory-based options.


Cryptographic coprocessors simplify IoT device security design.
Hardware-based security provides the strongest protection for IoT devices. Unlike software-based approaches, hardware security provides multiple layers of physical security, cryptographic algorithms, secure boot, encryption, secure key storage, digital signature generation, and authentication to block attacks from advanced hackers.

Maxim Integrated's DS28S60 DeepCover® security coprocessor is a hardware-based cryptosystem that provides a response system that helps users easily defend against security attacks.

The product includes ▲a high-speed 20MHz SPI slave interface for high-speed processing of security tasks ▲a fixed-function ECC/SHA-256/AES cryptographic toolbox ▲ChipDNA™ with Physically Unclonable Function (PUF) function.

The DS28S60 features built-in key exchange functionality, enabling components within IoT devices to exchange symmetric keys using asymmetric key algorithms, simplifying end-to-end encryption. Symmetric keys can then be used to encrypt and decrypt data transmitted between two IoT and sensor nodes and the cloud.

ChipDNA PUF technology provides strong protection against intrusions and reverse engineering attacks. The PUF circuit generates cryptographic keys using the naturally occurring random analog characteristics of core MOSFET elements. Keys are generated only when needed and are immediately erased without being stored on the chip. Attempts to probe or observe ChipDNA operation prevent the secret key from being leaked by modifying the underlying circuit characteristics.

The DS28S60 prevents the operation of counterfeit components within the system. Additionally, ChipDNA PUF technology is used to encrypt keys, confidential information, and all data stored on the device. Supports secure boot of the host processor with SHA-256 and ECDSA cryptographic toolbox features.

Separating complex cryptography and secure key storage from vulnerable host MCUs, the DS28S60 offers a 1.62V to 3.63V operating range and a 100nA power-down mode, making it well-suited for battery-powered IoT applications.

The product's cryptographic accelerator supports ECDHE key setup and is designed for client/server communication applications to prevent eavesdropping, tampering, and message forgery.

The DS28S60 features a fixed-function command set, eliminating the need for device-level firmware. While it does not have a built-in counter for peripherals with limited usage, counters can be implemented through user pages and some programming.



This article is a summary of a post titled "Here's an Easier Way to Keep Your IoT Devices Safe from Hackers" by Christine Young, a blogger at Maxim Integrated.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
이수민 기자