Showing posts with label PKI. Show all posts
Showing posts with label PKI. Show all posts

Wednesday, October 12, 2016

HOLISTIC SECURITY FOR THE AUTMOTIVE INDUSTRY



Bill Boldt
Business Development Manager, Security
Blackberry 
wboldt@blackberry.com

Security is emerging as perhaps the most important factor in the evolution of the connected autonomous car. Due to high profile hacks on cars, it is hard to argue that without security you can have safety. Cars are the most software intensive systems in the universe with far more lines of code than even a state of the art jet fighter. 




With being such complex digital systems they have become prime targets for attack, and that is where cryptographic countermeasures come in. 

Connecting the dots:  in the emerging software-defined world,  safety increasingly comes from security, while security comes from cryptography. Robust cryptographic security implementation is how you increase trust, and in a car every system must be trusted, including inside the car, in the smart  infrastructure, in emerging applications-based ecosystems, and in the manufacturing supply
chain. 


When considering automotive security, many factors come into play. Some are noted here (and were noted in a prior blog, but are worth repeating):
  •  Security assets (e.g.  crypto keys, serial numbers, etc.) must be installed into
    electronic devices such as Electronic Control Units (ECUs), domain/area controllers, and other processors at manufacturing time. This process is called "personalization"
  • Those electronic devices must be distributed to and be installed into vehicles in globally located factories
  • They must be warehoused worldwide for subsequent repairs, and be updateable at dealers and repair shops
  • In addition, aftermarket suppliers must be able to sell and update secure devices, and
    OEMs must have the ability to authorize electronic devices or not (e.g. enforce warranty  policies) 

And, there are many more.
  
To maintain the maximum amount of flexibility, personalization (provisioning) and updating should be moved as close as possible to the very last minute. Each car maker will be faced with the same
situation and will have to design and manage secure device manufacturing systems, secure updating systems, and security certificate management systems that are global and long
term in nature.


The way in which these systems get deployed will have to be designed to the specific logistical and security needs of the manufacturer.

Fortunately, the tools to do that are available from Certicom; namely, the Managed PKI
System and Asset Management System. 



Asset Management System
Certicom’s Asset Management System (AMS) installs cryptographic keys into devices (such as ECUs, domain and area controllers, processors, memory,key storage ICs, etc.) to ensure they are secure from tampering, counterfeiting, cloning, and other bad things that happen to good systems.
 

Personalization using Certicom’s AMS solution automates the secure distribution and tracking of digital assets, especially when used in conjunction with the Managed PKI services. 

Certicom’s Managed PKI Certificate Services helps high volume manufacturers secure devices and securely enforce ecosystem requirements. Authentication is enforced via certificates, which is a method that provides the highest levels of security. 



Mangaged PKI System
 
Certicom’s managed PKI system was initially created for BlackBerry mobile devices, which speaks to high security and volume production scale capabilities. 

Managed PKI performs four essential functions:
  1. ISSUE: Automatically issue certificates tvalidated devices 
  2. MANAGE: Track all of the issued certificates 
  3. RENEW: Automatically renew active devices 
  4. REVOKE: Disable certificates of lost or decommissioned devices






Security Design Consulting
The overall automotive manufacturing blueprint must be designed with best practices in mind right from the start, and BlackBerry Professional Services can help with that.  BlackBerry’s cybersecurity consulting and tools help to:


  • Identify the latest cybersecurity threats
  • Develop risk appropriate mitigation strategies
  • Implement and maintain IT security standards and techniques, and
  • Defend against the risk of future attacks
BlackBerry is making the proprietary security skill sets that made BlackBerry mobile device the most secure in the world available to the open market. BlackBerry's Professional Security Services teams provide design, analysis, response, and testing ("DART") via a range of services, as noted in the table below, among others:



 
With security skills honed in the mobile industry, industry leading cryptographic  expertise, and decades of automotive software experience, you can see that Blackberry brings it all together.

Thursday, August 18, 2016

Security Matters for the Software-Defined Car


Bill Boldt
Business Development Manger, Security, BlackBerry
wboldt@blackberry.com

  
Certicom, the crypto expert in the BlackBerry Technology Solutions family is positioned to lead the way to a secure software-defined future for the automotive industry –because when it comes to the security, real-world experience matters.
 

Certicom is a recognized leader in public key infrastructure (PKI) security design,innovation, and delivery. PKI is a foundational technology that has become the cornerstone of real world security across the internet, mobile, medical, financial, government,military, consumer, automotive, industrial, IoT, and just about every application that communicates information electronically. 

Public Key Cryptography uses public-private cryptographic key pairs to sign digital certificates and provide the essential elements of security, which are confidentiality, data integrity, authentication, and non-repudiation. PKI establishes the infrastructure that defines how digital certificates are created, distributed, stored, and revoked.



Public Key Cryptography Matters

It is not at all an overstatement to characterize Public Key Cryptography as having established the main way that security is provided throughout today’s (and tomorrow’s) connected world. In fact, anyone who has ever logged on to a secure web site such as e-commerce or e-banking has used Public Key crypto, most likely without even knowing it. it is already built into personal computers and smart phones, and it won’t be long before it is built into every embedded application as well. And, that is a very important notion to grasp.



Proven PKI solutions from world leading software and security infrastructure suppliers like Certicom increase device (e.g. semiconductor chip and board) security, fight counterfeiting and cloning of products and firmware, promote product and personal identity authentication, secure asset management in supply chains, and improve the security of numerous other applications, including the emerging Internet of things (“IoT”).

    
Public Key crypto's tremendous growth is being increasingly driven by two powerful forces: 1) the widespread adoption of autonomous communicating devices, and 2) the realization that such devices absolutely must be authenticated.

Supply Chain Security Matters
The long pole in the tent for  security in the software-defined car is in fact securing the supply chain. 

Security assets (such as crypto keys, uniqueserial numbers, etc.) must be installed into the devices at manufacturing time.  Devices must be distributed to and installed into vehicles in globally located factories. Devices must be warehoused worldwide for subsequent repairs.  Secure devices must be updateable at the dealers and repair shops.  Aftermarket suppliers must be able to sell and update secure devices. These requirements present a logistical tangle. Making a device such as an ECU or secure processor secure means that it will be unique. 


However, by definition that device cannot be used anywhere else.  It becomes a unique stock keeping unit (SKU), which is averse to the purpose of flexible, just in time manufacturing flows.  Security versus flexibility is a serious trade off that must be managed carefully. To maintain the maximum amount of flexibility, personalization and updating should be moved as close as possible to the very last minute.   That means it must happen not only in the factory, but in the field and via updates.  Each car maker faces the same issues, and will have to design and manage a secure device manufacturing system, security certificate management system, and a secure updating system – all of which must be global and long term in nature.
  

These are the type of things that Blackberry can provide  based upon decades of experience in securing mobile infrastructure and devices, to a level that no other company has done.



Experience Matters

Security is as elemental to an electronic system as DNA is to an organism—and security is BlackBerry’s DNA.


For the connected autonomous car of the future-- security has to be inside and outside the car, in the supply chain,  and updateable.  BlackBerry has the state of the art experience to to those things due to proven experience in making products secure, in high volumes, and in the supply chain.