This page was machine-translated and may differ from the original. View original
[Technical Contribution] ADI Vice President Don Loomis and two others: Technological Defense and Protection Methods for IoT Nodes
Dedicated security ICs, optimal for IoT security
IoT node security guaranteed throughout the product's lifespan.
Secure personalized flow and OTA updates available
IoT node security guaranteed throughout the product's lifespan.
Secure personalized flow and OTA updates available
The number of connected Internet of Things (IoT) nodes today has grown more than tenfold compared to just a decade ago, reaching approximately 10 billion, and this trend is continuing.
This growth also means more opportunities for malicious attackers.
The annual cost of cyberattacks is estimated to range from hundreds of billions of dollars to over a trillion dollars, and this number continues to grow.
Therefore, considering security is now essential to continuing the successful expansion of IoT. IoT security starts with the security of IoT nodes.
No company wants their name mentioned in a story with a headline like "Customer Information Stolen in Data Breach."
Additionally, connected devices must comply with government regulations, such as the U.S. Food and Drug Administration's (FDA) medical device regulations, cybersecurity requirements for Industry 4.0 critical infrastructure in the U.S. and Europe, and several new standards for the automotive industry.
These requirements require a high level of security, even if they do not explicitly mandate the use of hardware-based security.
On the other hand, IoT nodes are mostly large, cost-optimized devices, making it difficult to balance security and cost.
■ Building a security node using a 'Roof of Trust'
So, is there a way to design IoT nodes that are both cost-effective and secure?
Creating a secure IoT node starts with a “root of trust” (also called a “secure element”), a small, inexpensive IC designed to provide security-related services to the node.
Examples of such features include data encryption to maintain confidentiality and digital signatures to ensure the authenticity and integrity of information.
The ultimate goal of a root of trust is to protect the security keys used for data encryption or digital signing from being exposed.

▲Figure 1: ‘The concept of 'trust point' ensures the authenticity and integrity of security-related services.
The biggest challenge for 'root of trust' security ICs is to prevent physical attacks such as direct measurement and so-called 'side-channel attacks.'
■ Physically Unclonable Function (PUF) Technology
Unfortunately, direct measurement is not safe because it attempts to observe the internals of the microcircuit, and the memory technologies commonly used in general-purpose microcontrollers (EEPROM or flash) are not secure.
Attackers can use Scanning Electron Microscopy (SEM) to directly view the contents of memory at relatively low cost.
To mitigate these risks, the semiconductor industry has developed 'physically unclonable functions (PUFs)' technology.
PUFs are used to derive unique keys from the original physical characteristics of a chip.
These properties are much more difficult to measure directly, making it impractical to attempt to extract the key through direct measurement.
In some cases, the key extracted from the PUF encrypts the remaining internal memory of the root of trust, thereby protecting all other keys and credentials stored on the device.

▲Figure 2: PUF technology mitigates the risk of direct measurement of microcircuits.
Side-channel attacks are less costly and less direct.
An attacker can manipulate the data signature they want to manipulate.It takes advantage of the fact that electricity tends to leak from electronic circuits through power supplies, radios or heat dissipation.
Because there is a subtle correlation between the measured signal and the processed data, the value of the secret key can be successfully guessed by performing a suitably complex statistical analysis when the circuit uses that key to, for example, decrypt the data.
Trust points are designed to prevent such data breaches using a variety of countermeasures.
■ Application examples using security ICs
The benefits of a hardware-based "root of trust" are evident in the security application type shown in Figure 3. The protocol used is a challenge/response authentication protocol.
1. The meter requests a challenge from the pump to prepare for command transmission.
2. The pump sends a challenge value to the requester using a random number R.
3. The meter uses its private key to sign the command, a random number R, and some fixed padding. This operation is passed to the meter's trust point.
4. The pump verifies that the signature is correct and that the random number is the same number sent previously to avoid trivial retransmission of a valid command. This task is passed on to the pump's trust point IC.

▲Figure 3: Insulin pump authentication is a simple example of a trust point.
The security of this protocol relies on the secrecy of the private key used to authenticate commands and the integrity of the public key used to verify the authentication, in addition to the fact that each new attempt to send a command requires a new random number.
If these keys were stored inside a typical microcontroller, they could be extracted or manipulated, potentially creating a fake meter or pump, threatening patient safety.
In this case, the trusted point IC makes it much more difficult to counterfeit meters or pumps, manipulate authentication information, or tamper with communication protocols.
■ Benefits of a dedicated security IC
Typically, when a node device design is robust, the cost of compromising it far outweighs the potential rewards an attacker could obtain. Architectures that utilize dedicated security ICs offer significant advantages, including:
IoT security is a never-ending battle. Attack techniques continue to evolve, while security IC suppliers continue to strengthen countermeasures to make security IC attacks extremely costly.
Upgrading security ICs can improve the security of connected devices with little impact on overall device design and cost.
By focusing on core functions in a highly tamper-resistant physical environment, separate from the application processor, 'security proof' can be achieved more easily when assessing compliance.
This isolation also makes it very difficult to fully detect and remove vulnerabilities in the device's application processor, making it difficult to exploit.
If security IC manufacturers take on the commissioning work for security ICs early, it will be easier to ensure the security of IoT nodes throughout the product's lifespan.
This approach not only eliminates the need to share sensitive information with contract manufacturers, but also enables secure personalization flows and secure over-the-air updates. Overbuilding and cloning are also significantly more difficult.
■ Conclusion
Typically, a connectivity system consists of many elements, and security must be considered from the very beginning of the design.
Securing IoT nodes is a necessary, if not the only, step.
※ Contributor
Stephane di Vito, Senior Director, Micro, Security and Software, MTS, Analog Devices; Robert Muchsel, Fellow, Micro, Security and Software, Analog Devices; and Don Loomis, Vice President, Micro, Security and Software, Analog Devices
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.














