Hardware Secure Modules (HSMs) provide essential security for IoT devices by storing cryptographic keys in isolated, tamper-resistant hardware, enabling secure device provisioning, firmware integrity verification, and mass deployment without exposing keys in the main processor; this approach allows manufacturers to ship devices with encrypted firmware and pre-provisioned keys, while enabling secure distribution chains and delayed customer binding through encrypted manifests and join servers.
Hardware Secure Modules for LoRaWAN IoT Device Security at Scale
Added:[Applause] so thank you pressure to be here my name is Stefan Ingram I'm the city of talk pool Topol has been around in the Laura space since the very beginning where we are both producing devices and we are doing in networks mainly in the Nordics and in the Middle East so security you might think that hey I'm only doing a temperature sensor security how difficult can it be and how important is it so I took some measurements from my colleague that were away during the Christmas holiday here and yeah may be hard to say but in the upper you can see the temperature outdoor and - measurement indoors you might be able to say ok it was more flatter he was probably not home but maybe not that obvious and in the lower part it is the relative humidity that is also part of the sensor and also there you can see ok it's flattening out but it's you can't really tell that much from it but if you're looking for the absolute humidity for example then you can guess with one measurement and see if somebody's home or not because then the absolute humidity in the building are getting the same outdoor and indoor this is by the way a lot what we are doing when we are doing measurements with the construction company finding problems with molding and problems with heat and moisturi in in roof constructions so yes even if you do just a simple stupid temperature sensor IT security is key it is kind of an necessity that we are doing this right and this big risk that we are destroying kind of the IOT possibilities if we are not having a dealing with security in a proper way and Laura as technology is really good on security as well and it's a really an edge that we should push as soon as poss because we have the possibility with the overlay secure Network for example if you go into the industries that you're not part with insecure elements within the domain so of the industries but you can do that securely on top of it and having control way so I think security we should really take care of this is a real strength in in Laura and I would try to explain a little bit what we have done and why and the benefits of it and please if they have any questions yes you did so when we started up with the first devices back in 2016 we came from the telecom sector and doing smart phones and similar and you kind of what what the padding in the smart phones with the trust zones and key storage same cars and all of that so from the very beginning we started building insecure elements in our solutions and we are using a hardware based solution crypto memories using an atmel ECC 608 which is a separate unit it is the one in orange in the picture and it's really designed for with the separate processing separately EEPROM for storage of keys and you it is super secure you can't probe it down you you can't drill it down and it's a huge of effort even it to just crack one single device and and one of the benefits with is also that you can having a pre provisioned with the transport keys so when you are ordering it from for example microchip or from the other competitors there and you can get it with the transport key so so you having a secure anchor already from the beginning and you don't need to have any key handling at all invisible so what we are using is that we are dividing the keys in the secure element itself we are just storing in the factory an assault or announce that that is giving us enough information to know what the key is and we also not letting the EMS even if we are using a trusted manufacturing partner in Sweden which we really like it and appreciate they never see our firmware in clear-text they are only handling encrypted blobs that they are putting into the to the device and they are getting out and like a salt that is only giving kind of an ID so we can generate the keys back in our back ends as well and when you're doing devices and when you want to have it secure then that is the number of steps that you should go through and check and one of the first thing is looking at the the booting process of the MCU to harden the initial boot that is when deciding which of which firmware to to load and getting the basis up and running and that you can also lock the device if it's not the right software then it's a brick the second step is to secure the link between the the secure element in orange and the processor in red so it's really important that you are not able to probe the communication as well so you're setting up a secure link based on the pre shared secret that you know and that it's coming from the crypto memory manufacturer and when you're doing that then you can making sure that it is the right form that is downloaded it is your device and you can close it down if not everything is correct the next thing to do that is to D encrypt the firm and it's also part of being able to do secure farmer over-the-air or farmer upgrade in general both to see that it is a legit farmer version to see that it's not broken in the transmitted and doing that it is from an alleged source so if anybody is changing any bits in the information the integrity is false and the device doesn't boot so it is really secure than using a crypto memory also means that you don't need to handle any of the keys in in the MCU itself all security mechanisms are done in the crypt memory and by that it's never exposed not even in runtime that the keys are exposed in the MCU so that enhance the make is really harder to crack even a simple sensor and it's not also possible to like do backwards engineering to decompose the the files in order to find the attack vectors before the code itself and then on all the empty use and so one day is a lot of the debug interfaces programming interfaces and so on so during the initial after the initial boot it's also very important that all of those are closed down so even if you may be only able to break one device but that gives the attacker a possibility to start finding attack vectors in order to compromise the network and even if they're not able to come come to the information it could just be that they are threating into two for example the brick all your devices that you have out in field so today in security a lot of the threats are more towards ransomware or threats that they will destroy your assets rather than then also just stealing the information or injecting information and and when you're doing that then you can put the full MCU into read to read protect it so as soon as somebody is trying to read or trying to get into the MCU only the runtime memory and everything is just wiped so that there is no risks that anybody is doing it so these are kind of the basic steps to making a state of a North Hardware when it comes to security and following kind of the basis that is common in the cellphone parts using trusted elements but here we're using this horrid secure element instead okay so now you have secured the your device but hopefully all of us are hoping that we are able to get huge sales and the potential are huge of shipping hardware that is really important as well to getting a smooth distribution chain in order to having a mass deployment and the secure element can also help in that case together with for example what we are done together with the things industry so the targets that we are after it is that we could have one single SKU that can goes to all the different customers so just having a shelf product and also that we can support different distribution chains in several steps and having unique or unified way to handle the keys so we don't need to send a lot of encrypted firmware with the keys or not knowing who has access to the keys but rather just get it working and and another thing is also having the delayed customer binding so preferably when we're shipping out the devices we don't really need to know want to know exactly who the end client is it can be a small business that maybe is about five sensors or it can be used cooperation that is handling thousands of sensors it has to be kind of a unique or unified way to handle it in order to support the mass deployment and preferably also to having the full flow digitalized so we don't need to have the manual interactions between it but to have it from the de purchase order down to the factory and then to the end client having that full flow digitalized so we don't need to rely on the sales guy to really send the key and that the distributor should send the key to the end clients so this is our goal say in the design of the solution that we did with the TDI and what we came up with it's a the simplified and secure device pressuring so what we are doing is in our Factory and in any kind of in fact we were of course producing the the units we have the secure element in our our products and from that we are in the production creating a manifest with the Dassault l with the nouns for each one in order to understand which device has been produced and which one should be able to be claimed this are sent in the cryptid format and automatic into the to the joint server but by the things network a so even if this manifest or getting into the wrong hands it is encrypted so it's only can be the encrypted in the join server what did it distribution chain our kind of similar it's just shipping of hardware so we can have a shell product we can send it to the distributor a shell product and the we can send it out to whoever they don't need to keep track of okay which batch was it where can I find the key and so on it's all just sending the hardware distribution when the Installer comes at site we have the QR code so on all the devices he can scan the de cure devices and then claim it towards the the own server so when you're doing the join the keys and the information are already in the joint server and it works through any of the networks that is connected to the things networks join server and also on the open source version of the join servers here so by that we are both enabling massive deployment really easy distribution chains and so on and also make it easier for the end clients with the benefit that it is a total secure that there is no Open Text Keys seen anywhere and you can really rely that your security hasn't been compromised and taking that together with also the security handling of the the farmer and securing the device in general that that is a very good package and it's all dependent on the this secure element that is kind of the ultimate anchor when it comes to the security in the solution there so the TD and join server is supported by all the total products and it is a kind know of as you saw on this morning a lot of other vendors is also starting to support it for our sake we are mainly having devices when it comes to smart buildings when it comes to energy optimization or for some metrics of water or different customers solutions so in general I hope that I gave you some inspiration and some thoughts of when you're designing the products what to think of and how to really raise the bar and making sure that the lower devices that is out on the field or super sick or secure and that we are able to push it to the mass market very soon in an efficient way I don't know how quick I was but is there any questions on on the different topics always a bit exciting to ask questions in the audience it's all the way there if you hold on then I'll run up to you them so everybody can hear you it was here no oh sorry hi how much how much does that to the bomb cost to make it secure it's about 50 cent so so in Volume II it's not a huge cost and you are easily saving that in the distribution cost for it then of course it is some initial investment in getting the whole or sheet actually in place and so on but it's not a significant constant in the in the bomb how you make me go from one place to another surgery very good hello how do you change the owner of the sand so it happens sorry how do you change the owner of the sensor if the same so get from one hand to another hand a new pope okay yeah so this is the solution today it is to handle the initial join and the distribution chain from the factory derivatives and different distributors down to the end clients we have also we are looking also to having additional functions of the handing over sensors from one client to we think that that we can use it a similar mythology but that is not described in this presentation I think as we are sending out more and more sensors and more and more sensors are also built into into buildings or more built it I think it's a very relevant question and absolutely something we are looking in to see how we can securely both share the the secrets doing the and protecting the data so only the legit owner of the sensor can decrypt the data but the solution here this guard is not handling that part okay there is one last question here yeah how you handling the manifest file upload from the factory floor to the joint server securely yeah so from the factory we were getting the the salt for the different parts that goes into our production server and from the production server we are automatically creating one file per batch that we are producing and that one we are signing with the keys for the things network joint server or any kind of join service that we would like to have those specific keys and then we were sending it over in secure secure way to do the joint server and then the the keys can be derived in the joint server so so it's getting all automated from production to us but it go through our production servers in our R&D so the answer to the question yeah okay thank you so much stays on Lindgren okay thank you you
Up Next

Chainlink LINK Explained: Oracle Networks and Cross-Chain Infrastructure
@CryptoTips
44K views•2024-05-22

Triumph of Orthodoxy Icon: Byzantine Art & History Explained
@BenCallan
2.1K views•2024-08-06

FastAPI vs Flask vs Django: Choosing the Right Python Web Framework
@TechWithTim
302.5K views•2024-05-26

Game of Thrones Opening Credits: A Cinematic Analysis
@gameofthrones
46.3M views•2011-04-18
Related Study Plans & Knowledge Roadmaps
Structured learning paths in General & Interdisciplinary Studies







































