This page was machine-translated and may differ from the original. View original

[Planning] IoT: Transforming Our Lives, Implemented with Cutting-Edge Technology - Security

Google 우선 소스Published2021.05.28 13:52
Serial order
(1) May 17th Sensor
(2) Connectivity on May 20th
(3) Actuator on May 24th
(4) Microcontroller on May 26
(5) May 28 Security


[Editor's Note] When smoke is detected inside a home, a fire detector sounds, nearby firefighting equipment activates, and an emergency call is sent to the homeowner and the fire department. Beyond firefighting, the implementation of such systems, which operate without human intervention, has become readily available and widespread in our daily lives, and it is expected that further advancements will continue in our daily lives in the future. Systems that connect and operate through the Internet of Things (IoT) without human intervention are called the Internet of Things (IoT) . The IoT is being applied to many aspects of our lives, whether we are aware of it or not, such as healthcare, power, gas, parking, and home appliances. Accordingly, this magazine has prepared a five-part series to examine the cutting-edge technologies that make the Internet of Things possible.




Security , IoT 'Complete'

Difficulty in Applying IoT Security Technology: Relative Security Vulnerability Issues
Consideration from planning and design, meeting diverse system requirements is essential.

■ IoT, exposed to various security threats, security solutions are essential

The Internet of Things (IoT) is exposed to various security threats because devices and sensors are connected through heterogeneous wired and wireless networks and protocols, and the operating systems and software for this are mixed.

Unlike traditional methods, IoT provides innovative services through sensor-based information collection. However, it has the problem of being difficult to understand the personal information processing flow and having limitations in post-event responses when problems arise.

Anxiety stemming from a lack of understanding can lead to distrust in services and companies, resulting in unnecessary social costs due to disputes such as lawsuits. Furthermore, in environments where large amounts of personal information are processed in real time, personal information leaks can lead to large-scale, irreversible damage.

For example, in 2013, a demonstration was held in Las Vegas, USA, assuming a situation where a camera installed in a smart TV was hacked and private videos were leaked, and in 2014, the US CIA used TV malware (Weeping Angel) that appears to have been developed in conjunction with the UK's MI5 for hacking. Even when the TV was turned off, it collected sounds heard in the room and sent them to the CIA server via the Internet, or hacked Wi-Fi usernames and passwords by recovering the Wi-Fi password stored on the TV.

As IoT services spread to everyday life, including home appliances, attacks on all Internet-connected products (IoT), including home wireless routers and air conditioning and heating equipment, are becoming a reality.

Distributed denial of service (DDoS) attacks primarily target wireless routers commonly used in homes. These wireless routers typically do not have antivirus software, a basic security solution, installed, and their management is unclear.

Moreover, most users use their wireless routers without changing their initial settings. While some manufacturers are strengthening security measures following the recent spate of wireless router hacking incidents, most homes are still exposed to cyber threats.

In the IoT era, the number of products connected to the Internet is increasing exponentially, so all home and home appliance IoT products, such as refrigerators and cleaning robots, that are connected to the Internet can be targets of hacking.

Additionally, IoT products have the problem of being relatively vulnerable to security because, unlike general ICT systems, it is difficult to apply security technology to them.

Therefore, security must be considered from the IoT planning and design stage, and a security solution that meets various system requirements is needed.

■ Latest security patches and blocking of unauthorized access

According to the Korea Internet & Security Agency's Home and Appliance IoT Security Guide, if the software that makes up a home and appliance IoT product was developed using protocols, libraries, APIs, packages, open sources, etc. that have known security vulnerabilities, the firmware and operating system may also be vulnerable to security, so the product must be inspected to remove security vulnerabilities.



▲Common security items and response measures (Source: IoT Security Alliance, Home and Appliance IoT Security Guide)


First of all, during the development stage, 3rd party software is applied with the latest security patches. Products must be developed using the latest versions. Furthermore, after product launch, if a serious security vulnerability arises in third-party software used in the product and urgent security patches are required, security patches must be developed based on the latest versions of the third-party software and distributed promptly.

Externally exposed ports are easy to identify for their type and function, and are easily accessible without the use of separate access tools, making them a vulnerable target for attacks. Ports not required for product operation, such as USB, RS232, Ethernet, and SD card slots, should be removed or disabled to fundamentally block unauthorized external access. Furthermore, when changing between development and mass-production PCBs, input/output ports should be completely removed or disabled before release.

Mass-produced products must completely remove internal input/output ports or debugging ports, and if internal ports are to be maintained for updates or troubleshooting, the JTAG port must be disabled or access must be controlled using a password.



▲Example of a hardware board for a webcam product (Source: IoT Security Alliance, Home and Appliance IoT Security Guide)


In general, security vulnerabilities in hardware can arise from direct access to the hardware's data bus and control signals. Accordingly, it is necessary to implement functions to prevent physical probing and detect and respond to unauthorized manipulation.

Infineon Leads the Way in Building Digital Trust


Meanwhile, Infineon is actively working to build trust in the digital world through security.

We build security and privacy into embedded systems, increasing trust in the IoT and providing security solutions that meet diverse design challenges and system requirements.

The easy-to-integrate Infineon OPTIGA™ family offers a wide range of products for embedded security solutions and secure cellular connectivity.

/cms/kr/make-iot-work/">SECORA™ is a one-stop security solution that integrates the operating system (OS), enabling cost-effective, fast, and flexible implementation.

The PSoC™ 64 AWS Standard Secure MCU includes a hardware-based root of trust (RoT) and runs Trusted Firmware-M secure firmware, enabling secure boot and secure firmware updates along with other security services.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자

WEBINAR종료
Implementing Extensive IoT with Global Cellular Connectivity
  • 2021.06.03 10:30~12:00
  • Infineon · 김영욱 부장, 하태수 부장