This page was machine-translated and may differ from the original. View original
[Technical Contribution] IAR-Asset Protection: Protecting Intellectual Property Rights
IP protection and integrity must be fully secured with SW.
IAR Embedded Trust provides IP protection based on advanced encryption technology.
Simplified development process, enabling IP protection without developer expertise.
IAR Embedded Trust provides IP protection based on advanced encryption technology.
Simplified development process, enabling IP protection without developer expertise.
Security is emerging as a top priority in the embedded industry, and for good reason.
It's natural to want your product to succeed, but as it becomes more popular, the likelihood that bad people will be interested in it also increases.
Any weakness can be an avenue for stealing your IP or a means to re-engineer your product.
Also, if there is any part that has this potential, it will definitely lead to actual damage.
This type of damage occurs regardless of location, including manufacturing facilities and users' workplaces.
Additionally, external subcontractors may produce products even when the order has not been placed, stealing profits that should be taken by the company, potentially negatively impacting brand and customer relations.
This is obviously very unfair, but the reality is that system attacks are happening, and even the smallest mistakes can have serious consequences.
■ Serious impact on the Internet of Things counterfeit parts market and reputation
Consumer brands have long suffered from counterfeiting and piracy. But in the world of connected devices, counterfeit components can potentially cause far more serious damage to markets, brand reputations, and safety.
The Internet of Things clearly offers numerous benefits across all verticals within industries, including improving business processes, streamlining them, and reducing downtime.
On the other hand, the fact that devices are connected to the Internet means that the points of compromise within the network increase significantly.
Significant problems can arise, especially when companies are unable to clearly determine the authenticity of devices and products within their manufacturing supply chain.
■ Counterfeit parts pose a safety threat
Moreover, counterfeit parts pose a safety hazard. There is no guarantee that the final software IP has not been tampered with, and that the hardware has the level of robustness and reliability that the OEM claims.
Stolen IPs can be modified through deceptive methods and may include backdoors, side channels, etc.
A breach of integrity means that modified software IP could potentially be exploited to infiltrate safety-critical connected systems (such as modern automobiles).
Using counterfeit parts that do not meet the specifications of genuine products may result in the device being monitored by those parts not meeting the necessary operational requirements.
This is especially dangerous when the newly installed counterfeit parts have lower specifications or quality than the original device.
Depending on the type of system or application that uses these components, the effects can vary greatly and can lead to unexpected and serious consequences.
Take cars, for example, where autonomous driving is part of a system that could compromise safety-critical functions.
Such failures can occur when monitoring of environmental properties to prevent accidents is inaccurate or when judgments about errors are incorrect.
Additionally, the medical field can also be a problem. If software IP is tampered with without permission, it could lead to inaccurate results, which could cause problems for devices that rely on accurate body temperature measurements, for example.
This may result in the drug not being administered in the correct dosage, which may result in serious harm or even death to the patient.
Typically, distributed supply chains run the risk of hackers intercepting software IP and injecting backdoors or malicious code.

▲Figure 1: Software IP without integrity protection can be changed by hackers.
■ Functional Safety and IP Protection
IAR's Embedded Trust provides IP protection based on advanced encryption technology.
The integrity and authenticity of the firmware is verified by binding to the Secure Boot Manager (SBM) provided by IAR through digital signature.
These SBMs are protected from tampering by their chip hardware and personalization via public keys. Public keys enable integrity checking and can verify the authenticity of security-critical firmware.
Additionally, an encryption-based confidentiality protection mechanism can be added to protect the security-critical firmware.
This prevents reverse engineering and software IP from being stolen.
Because the software is encrypted from the development environment (IAR Embedded Workbench with Embedded Trust) until it boots and runs on the System on Chip (SoC).

▲Figure 2: Sealing software IP with a digital signature to effectively prevent fraudulent modifications.
■ IP Protection with Embedded Trust
A key design requirement for Embedded Trust is to simplify the development process.
There is no need for development engineers to have specialized knowledge of encryption or encryption key management when applying IP Protection to an application.
IAR's IP Protection products can be set up in just a few simple steps.
One of the functions provided by IP Protection is 'Basic signature checking', which can protect software IP from unauthorized modification and ensure that only authorized firmware can be booted.<br />
This feature can be further developed to include "full encryption" in firmware, providing additional protection against reverse engineering and IP infringement.

▲Figure 3: IP Protection feature setup wizard. Authenticity, integrity (Basic signature checking), or confidentiality protection (Full encryption).
As an added protection, it also has an anti-rollback feature that prevents the firmware from being rolled back to a previous version.
The 'Version number check' function prevents the use of older versions that may have security vulnerabilities during the firmware update process. This feature has the ability to prevent the exploitation of security vulnerabilities that existed in older versions.

▲Figure 4: Block attacks using older versions of firmware through the version number verification function setup wizard.
The question of how to protect intellectual property is becoming an increasingly difficult one for many companies.
This is because these intellectual properties are becoming core assets of companies.
Embedded application development is often considered a significant investment, requiring years of human resources and effort to bring a product to market.
Embedded Trust enables enterprises to easily strengthen the protection of their investment assets by enabling them to apply fundamental security measures such as signing and code base encryption, and preventing firmware downgrades through anti-rollback policies.
With robust security features, users will not only achieve complete IP protection from development to deployment, but also have improved device identity management and trustworthiness.
※ writing
IAR Systems
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.


















