Telecoms, Datacoms, Wireless, IoT


The five pillars of secure IoT design

19 April 2017 Telecoms, Datacoms, Wireless, IoT

For any industrial Internet of Things (IoT) application, ensuring signal integrity is crucial for safety and operational reliability. However, even the most robust system has many attack surfaces that are vulnerable to would-be ­hackers intent on compromising a system. This is unacceptable for high-reliability systems in general, but as more contextual information gets added, including time and position, the level of compromise increases dramatically, so gaps in security must be identified and closed at every opportunity.

In the case of an IoT sensor, a chain of trust must be established from the sensor to the microcontroller and wireless module, and all the way through to the end application. In industrial applications for the IoT, every attack surface must be secured in order to establish a chain of trust. u-blox refers to this as its five pillars of secure IoT design:

• Device firmware and Secure Boot.

• Communications to the server.

• Interface security.

• Enforcing API control.

• Robustness that includes handling spoofing/jamming.

Secure Boot ensures that a device is executing the intended firmware by authenticating at each stage before booting the next process. Also, while over-the-air updates are useful for mass uploads of many widely deployed IoT devices, they create an attack surface that can be vulnerable, so all firmware must first be validated before being installed. A good implementation will include a backup of a previously authenticated image to allow backtracking if there is a problem.

At the communications or transport layer, a device needs to be able to authenticate itself with the server and all exchanged data should be encrypted, with no possibility of a ‘man in the middle’ attack. Secure key management will allow for this, even on a per-session basis.

The defined APIs that provide access to device functionality are also a vulnerability that must be addressed, though they are often overlooked. This is particularly insidious as hackers usually have a lot of time to look for open APIs and explore their relationship to device functionality and features, which sometimes might include access to paid services. Also, developers often use undocumented APIs for their own test and configuration purposes, so these must be protected too, using the same formal authentication and authorisation processes as used for all APIs.

The fifth link in securing IoT devices involves ensuring robustness, such as when facing jamming or spoofing attempts that might undermine the device’s ability to get accurate position data from a GNSS. The design must be able to detect that the reported information is not accurate and report the situation to the user or IoT network operator.

For more information contact Andrew Hutton, RF Design, +27 (0)21 555 8400, andrew@rfdesign.co.za, www.rfdesign.co.za



Credit(s)



Share this article:
Share via emailShare via LinkedInPrint this page

Further reading:

Wireless connectivity expanded
iCorp Technologies Telecoms, Datacoms, Wireless, IoT
Espressif Systems has introduced two new members of its ESP32 wireless SoC family: the ESP32-E22, the company’s first Wi-Fi 6E connectivity chip, and the ESP32-H21, an ultra-low-power Bluetooth LE microcontroller aimed at coin-cell and battery-powered devices.

Read more...
Integrated X-band radar front-end module
RF Design Telecoms, Datacoms, Wireless, IoT
Qorvo has introduced an X-band radar front-end solution that enables defence system designers to achieve higher performance without increasing size, weight or prime power.

Read more...
Introducing Aurata
CST Electronics Telecoms, Datacoms, Wireless, IoT
Antenova has launched Aurata SR4L112: a compact, high efficiency embedded 4G/LTE antenna engineered for long, narrow PCB designs.

Read more...
Multi-constellation GNSS module in a legacy-compatible footprint
Altron Arrow Telecoms, Datacoms, Wireless, IoT
Telit Cinterion has announced the SE869eK2L, a single-frequency L1 GNSS module designed to help device manufacturers upgrade legacy positioning designs with improved performance and cost efficiency, while preserving design continuity.

Read more...
Quectel expands 5G portfolio
iCorp Technologies Telecoms, Datacoms, Wireless, IoT
Quectel expands 5G portfolio with new Qualcomm- and UNISOC-based modules.

Read more...
Surface mount power amplifier for high-power applications
RF Design Power Electronics / Power Management
The GNA-63-5W+, from Mini-Circuits, is a GaN MMIC Power Amplifier (PA) designed for demanding RF applications requiring high efficiency, excellent linearity, and a compact footprint.

Read more...
Compact RTK design: More than just the receiver
iCorp Technologies Editor's Choice Telecoms, Datacoms, Wireless, IoT
In practice, engineers building compact RTK products keep discovering the same thing: the hardest component in the system is no longer the receiver. It is the antenna.

Read more...
Microchip advances Space-Grade timing performance
ASIC Design Services Telecoms, Datacoms, Wireless, IoT
Microchip Technology has expanded its atomic clock portfolio with the radiation-tolerant Space CSAC-SA65, a Chip Scale Atomic Clock designed to deliver precise timing for space systems.

Read more...
Channel emulator for 6 G and Wi-Fi 7/8
Concilium Technologies Telecoms, Datacoms, Wireless, IoT
With 400 MHz instantaneous bandwidth and support for carrier frequencies up to 23,6 GHz, Vertex 6.0 is the industry’s first channel emulator designed for next generation 6 G and Wi-Fi 7/8 testing.

Read more...
Secure, low-power Bluetooth LE SoC
NuVision Electronics Telecoms, Datacoms, Wireless, IoT
Silicon Labs unveils BG2B, its lowest-power Bluetooth LE SoC with industry-leading power efficiency, security, and integration.

Read more...









While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd | All Rights Reserved