{"id":9678,"date":"2017-11-06T18:35:36","date_gmt":"2017-11-06T18:35:36","guid":{"rendered":"https:\/\/www.techdesignforums.com\/practice\/?p=9678"},"modified":"2019-03-31T07:19:27","modified_gmt":"2019-03-31T07:19:27","slug":"fighting-the-war-of-escalation-in-embedded-systems-security","status":"publish","type":"post","link":"https:\/\/www.techdesignforums.com\/practice\/technique\/fighting-the-war-of-escalation-in-embedded-systems-security\/","title":{"rendered":"Fighting the war of escalation in embedded systems security"},"content":{"rendered":"<p>Security involves trading off the cost of securing something with the value that is being protected. As our lives move online, the variety of devices that can expose us to significant losses is rising steadily as hackers learn how to exploit security flaws in everything from nannycams to network routers to access valuable data \u2013 such as personal information and online identities.<\/p>\n<p>The challenge for designers, therefore, is to find ways of providing high levels of security in low-cost devices that, in themselves, are not worth a hacker\u2019s attention but which become worthwhile targets because of their role as gateways to more valuable information.<\/p>\n<p>Threats can be applied at various levels. Communications to and from a device can be subject to sniffing of sensitive data, such as passwords, direct remote attacks via backdoors, and indirect attacks through remote nodes. Software, in turn, can contain malware such as viruses and rootkits, exploit buffer and\/or stack overflows, or tamper with privilege levels to give unauthorized users greater powers to explore and control a system than they should have.<\/p>\n<p>It\u2019s important to understand and protect against these sorts of attacks. However, it could be argued that they are less important than attacks against the underlying hardware of a system. Hardware can be attacked through non-invasive means such as illicit access to debug ports or side-channel analysis, and through invasive means such as decapsulation and direct probing. Once the hardware is compromised, all bets are off.<\/p>\n<p>The security issue is becoming more acute as embedded devices, such as those being developed to become part of the Internet of Things, start using embedded SIMs (eSIM or eUICC) to provide what are presumed to be secure identities. As system developers increase the level of trust they attribute to such devices, the value of the devices as hacking targets increases.<\/p>\n<p>SoC designers are, by now, well-versed in fighting the war of escalation between those with secrets to protect (either locally-held information or potential access to other systems) and hackers who want to exploit security vulnerabilities for gain.<\/p>\n<p>For example, they\u2019ll provide watchdog timers to protect a chip against efforts to learn about its function by tampering with its operation. They\u2019ll lock down debug ports, so they aren\u2019t open to all-comers for exploitation. They\u2019ll obfuscate how much time and power it takes to run each instruction, so that hackers can\u2019t learn anything about the device\u2019s operation from analyzing these profiles. They\u2019ll perform integrity checking on data and instruction paths to negate attacks using fault injection. And so on.<\/p>\n<p>Synopsys has been developing secure IP incorporating many of these preventive measures for a while now, and its latest release is a pre-verified DesignWare ARC Secure IP Subsystem, which provides a combination of trusted hardware modules and a supporting software environment.<\/p>\n<p>It is based around either a DesignWare ARC SEM110 or an SEM120D Security Processor with SecureShield technology, which enables the creation of a Trusted Execution Environment (TEE) for secure code execution, secure handling of assets, and tamper protection. The ARC SEM processors also have side-channel protection; a tamper-resistant pipeline with inline address scrambling; error detection and parity checking on memories; and secure debug to protect against theft of keys, code or other sensitive information.<\/p>\n<p>The Secure IP Subsystem has secure instruction- and data-memory controllers that enable code or data to be stored in encrypted form outside the Secure Subsystem, and then decrypted on the fly as the processor fetches it from memory.<\/p>\n<em>No URL for image<\/em>\n<p>Cryptography options include dedicated hardware cryptography engines, to handle typical ciphers, and hashing algorithms such as AES, DES\/3DES, SHA-256, RSA and ECC. The ARC Secure IP Subsystem also includes access to the DesignWare Cryptography Software Library, which has been validated by NIST.<\/p>\n<p>Software and development support includes a variety of tools to enable the creation of secure systems. In addition to the crypto library, the ARC Secure Subsystem software offering includes secure boot, the SecureShield runtime library, hardware abstraction layer and device drivers. Provisioning tools include a secure boot toolkit, and a tool for creating firmware that can work with the secure external memory controller. Synopsys has worked with third-party and open-source software to provide a complete embedded SIM solution. This includes JavaCard OS, the eSIM stack, and the embARC open software platform.<\/p>\n<h2><b>Further information<\/b><\/h2>\n<ul>\n<li>Learn more about <a href=\"https:\/\/www.synopsys.com\/designware-ip\/processor-solutions\/designware-arc-subsystems.html\" target=\"_blank\" rel=\"noopener noreferrer\">DesignWare ARC Subsystems<\/a><\/li>\n<li>Learn more about <a href=\"https:\/\/www.synopsys.com\/dw\/ipdir.php?ds=arc-sem\" target=\"_blank\" rel=\"noopener noreferrer\">ARC SEM Processors<\/a> and <a href=\"http:\/\/www.secureshield.com\" target=\"_blank\" rel=\"noopener noreferrer\">SecureShield technology<\/a><\/li>\n<li>Learn more about Synopsys <a href=\"http:\/\/www.synopsys.com\/IP\/security-ip\/Pages\/default.aspx\" target=\"_blank\" rel=\"noopener noreferrer\">DesignWare Security IP Solutions<\/a><\/li>\n<\/ul>\n<h2><b>Author<\/b><\/h2>\n<p>Rich Collins is product marketing manager, IP subsystems, Synopsys.<\/p>\n<h2><b>Company info<\/b><\/h2>\n<address><i>Synopsys Corporate Headquarters<\/i><\/address>\n<address><i> 690 East Middlefield Road<\/i><\/address>\n<address><i>Mountain View, CA 94043<\/i><\/address>\n<address><i>(650) 584-5000<\/i><\/address>\n<address><i>(800) 541-7737<\/i><\/address>\n<address><i>\u00a0<\/i><i><a href=\"http:\/\/www.synopsys.com\" target=\"_blank\" rel=\"noopener noreferrer\">www.synopsys.com<\/a><\/i><\/address>\n<h2><\/h2>\n","protected":false},"excerpt":{"rendered":"<p>The challenge for designers is to find ways of providing high levels of security in low-cost devices that have become worthwhile targets because of their role as gateways to more valuable information.<\/p>\n","protected":false},"author":329,"featured_media":9682,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1242,1385],"tags":[1178,2116,1770],"coauthors":[996],"class_list":["post-9678","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-architecture-design","category-choose-buy-ip","tag-cryptography","tag-embedded-security","tag-iot","workflow-expert-blog","workflow-featured","workflow-technique","workflow-up-to-date","organization-synopsys"],"_links":{"self":[{"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/posts\/9678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/users\/329"}],"replies":[{"embeddable":true,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/comments?post=9678"}],"version-history":[{"count":0,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/posts\/9678\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/media\/9682"}],"wp:attachment":[{"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/media?parent=9678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/categories?post=9678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/tags?post=9678"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.techdesignforums.com\/practice\/wp-json\/wp\/v2\/coauthors?post=9678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}