This page was machine-translated and may differ from the original. View original

[Planning IIoT Interview] Infineon: Smart Factory Security with Robust Hardware-Based Solutions

Google 우선 소스Published2017.03.02 16:09
Tamper-proof trust anchors, storing keys and certificates as well as encryption.
TPM is suitable for use in high-end equipment in smart factories.


As smart factories rapidly evolve, manufacturing faces new challenges. Distributed, automated smart factories, heavily reliant on network technology, face constant cyber threats.

As systems become more vulnerable to external attacks, the need for robust security becomes increasingly crucial. To address this, manufacturers must leverage the extensive experience and expertise of security specialists. Hardware-based security solutions, such as Infineon's OPTIGA TPM and OPTIGA Trust products, provide optimal security for Industry 4.0 and smart factories.

We spoke to Lee Sang-hoon, Head of Infineon Korea's Chip Card and Security Business Unit, about the background and principles of hardware-based security solutions.


▲ Lee Sang-hoon, Vice President / Infineon Korea Chip Card and Security Business Division

Q. First of all, the Industry 4.0 environment requires a security environment different from the existing one. How do you think the security environment has changed?

In the Industry 4.0 environment, manufacturing will become a distributed, automated smart factory heavily dependent on network technology. This increased connectivity increases vulnerability to external attacks, necessitating even more robust security. Any digital threat—whether fraudulent firmware updates, counterfeit parts, malware, or unauthorized manipulation—can halt entire production lines and incur significant losses for manufacturers. Even the slightest security breach in a company's infrastructure can lead to unexpected process interruptions, theft of sensitive data, and negatively impact a company's reputation.

Q. Next-generation industrial environments require dedicated security devices that function as hardware-based trust anchors. Hardware-based security devices have proven their reliability through significant advancements. What advantages do they offer compared to software-based security features?

It's a long-standing fact that software alone is insufficient to secure systems. Hardware-based security devices, by their very nature, are more difficult to manipulate than software. Cards and electronic ID cards demonstrate that similar technologies can effectively protect personal information. Hardware-based tamper-resistant trust anchors not only provide encryption capabilities, but can also securely store confidential information such as encryption keys and certificates.

"Using a dedicated security chip eliminates the need for additional encryption processes."

Q. What are the benefits that manufacturers can gain by using dedicated security chips for industrial applications?

Manufacturers benefit from using dedicated security chips because they eliminate the need for additional processes to encrypt keys transmitted to their equipment. This reduces the cost of security infrastructure in factories and enhances process security. Security chips also enable greater flexibility in manufacturing. For example, when manufacturers outsource production, they can securely transmit keys from a personalized server to a hardware anchor. This provides manufacturers with more options when selecting subcontractors. Because it's not necessarily essential for third-party vendors to meet the highest security requirements.


Q. What are the security differences between using a microcontroller with an integrated hardware encryption engine and using a dedicated security controller?

Microcontrollers with integrated hardware encryption engines are available. These microcontrollers can be useful when performance is more important than security. However, while these standard microcontrollers may offer improved performance, they don't offer the same security benefits as dedicated security controllers. Dedicated security chips execute encryption algorithms in an environment completely separate from the processor. Furthermore, standard microcontrollers lack measures to defend against physical attacks. Therefore, when you want to significantly improve security, you should use a dedicated security controller such as Infineon's OPTIGA™ family.

Q. Servers, gateways, and terminals that transmit information to other factories must be equipped with a Trusted Platform Module (TPM) to protect and verify the integrity of the equipment. How is Infineon applying this TPM to protect industrial applications, and what are its features?

Trusted Platform Modules (TPMs) are ideal for use in high-end equipment in smart factories. Defined by the Trusted Computing Group (TCG), TPMs are security chips that enable more secure computing environments. While primarily used in the computer industry, other sectors, such as industrial automation, are increasingly recognizing their utility for protecting industrial applications. Infineon's OPTIGA™ TPM is a highly robust security controller for applications such as PLCs, HMIs, and gateways.

Infineon's OPTIGA™ TPM complies with the international standard ISO/IEC 11889 and offers standardized features. This allows customers to leverage the expertise gained through years of experience and delivered through its products from a specialist like Infineon, while leveraging existing security solutions. This reuse of existing software and processes reduces security risks. Because these professional solutions have already undergone rigorous testing cycles and are market-proven, you can be confident they will meet stringent regulatory requirements.

"Providing a partner network to make security solutions more accessible to customers."

Q. Smart factories are comprised of multiple layers of systems. Each system will have different security requirements. How should we address these challenges? Could you provide some representative examples from Infineon's embedded security solutions portfolio?

Nodes, sensors, and I/O modules require basic security in the form of authentication. This requirement can be met with the OPTIGA™ Trust SLS 10ERE. This chip implements asymmetric encryption and comes in a very compact package (2mm x 3mm), making it easy to integrate into standard electronic devices. Therefore, the OPTIGA™ Trust can be integrated into I/O modules, allowing the PLC to verify whether the I/O module is a genuine component.

For PLCs, power supplies and equipment that require a more general interface, the OPTIGA™ Trust E SLS 32AIA product provides high-quality authentication using an I2C interface. Another important feature that differentiates the OPTIGA™ Trust E from standard microcontrollers is that it provides hardware-based security to prevent tampering (encrypted memory, prevention of key extraction via side-channel attacks, etc.). Therefore, sensitive information such as keys and data stored in the OPTIGA™ Trust E is highly protected. Furthermore, both OPTIGA™ Trust and OPTIGA™ Trust E provide host-side software, facilitating easy integration of the chip into various types of components or equipment. The Trusted Platform Module (TPM) is suitable for use in high-end equipment in smart factories. A TPM, as defined by the Trusted Computing Group (TCG), is a security chip that enables a more secure computing environment. Infineon's OPTIGA™ TPM is a very powerful security controller for applications such as PLCs, HMIs, and gateways.

Q. What kind of customer support does Infineon provide to aid product design in the IoT solution sector, and what partnerships are being built to ensure customers have easy access to security solutions?

The IoT solutions landscape is a vast and rapidly evolving ecosystem, creating additional synergies for security solution providers and system integrators to collaborate to address diverse IoT security needs. The Infineon Security Partner Network (ISPN, http://www.infineon.com/ISPN) aims to make security solutions more accessible to customers. ISPN partners offer a wide range of security solutions for IoT device and application developers, leveraging hardware-based security as a trust anchor for their systems. This platform allows solution providers across different aspects of the ecosystem to share new ideas and experiences, enabling them to develop innovative security use cases and collaborate more collaboratively to meet customer security needs.

Meanwhile , Infineon's Vice President Lee Sang-hoon will present a more detailed presentation on this topic at the Industrial IoT Innovation Day seminar ( http://www.e4ds.com/seminar ) . Go directly to seminar registration -> http://www.e4ds.com/seminar
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
신윤오 기자