This page was machine-translated and may differ from the original. View original

Nordic Semiconductor Announces Secure OTA Firmware Update Enhancing Device Security

Google 우선 소스Published2016.09.05 14:19
Latest nRF5 SDK Support, Preemptively Preventing Malicious Device Upgrade Attacks

Nordic Semiconductor's (Korea Branch Manager Soo Chul Choi) latest nRF5 SDK v12.0 supports secure signature-based OTA-DFU (Over-The-Air Device Firmware Update) to enhance application update security performance.

This SDK uses authenticated secure signatures to ensure device updates occur only from trusted, verified sources, thereby preemptively preventing damage from malicious device upgrade attacks.

John Leonard, Product Marketing Manager at Nordic Semiconductor, noted that "security is the most critical issue for IoT (Internet of Things) companies" and stated, "firmware upgrades for products are fundamental and important tasks that must be conducted from trustworthy sources."

Leonard also said, "For most manufacturers, software development is a considerably complex task that multiple teams must complete according to deadlines, and after the product is released to market, all possible bugs must be resolved. At the same time, manufacturers want to introduce the latest cutting-edge features to their products to ensure optimal performance and maintain customer relationships. Therefore, executing software and firmware updates is an essential function. For Bluetooth Low Energy products, the most convenient and secure method for this is secure signature-based OTA-DFU updates, and Nordic's latest nRF5 SDK v12.0 supports all of this."

The typical public/private key security structure currently in use maintains 1:1 security with the public key distributed and the private key remaining solely with the sender. Nordic's nRF5 SDK v12.0 allows developers to generate encryption keys in various ways.

Leonard mentioned, "Through considerable development effort, Nordic has been able to provide flexibility allowing developers to generate encryption in various methods of their preference." This includes methods using ECDH with the P256 curve for secure wireless access of Bluetooth® Low Energy technology, as well as methods using Nordic-certified examples.

Nordic also supports PC tools commonly available across all platforms and mobile tools for Android and iOS for secure DFU application development.

Meanwhile, if a secure OTA-DFU is interrupted, the 'Resume-from-Failure' feature allows the update to resume and complete from the last successful point, eliminating the need to restart the entire upgrade process from the beginning.
To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
홍보라 Reporter