SlideShare a Scribd company logo
1 of 10
Download to read offline
A New Hardware-Level
Approach to Fix the
Internet of Broken
Things
C e s a r e G a r l a t i , C h i e f S e c u r i t y S t r a t e g i s t , p r p l
F o u n d a t i o n
A New Hardware-Level Approach to
Fix the Internet of Broken Things
Cloud Connect China 2016
Cesare Garlati, Chief Security Strategist, prpl Foundation
Securing the Internet of broken things
Source: Remote Exploitation of an Unaltered Passenger Vehicle, Dr. Charlie Miller and Chris Valasek, August 2015
1.4M
FIAT CHRYSLER
RECALLS 1.4
MILLION
VEHICLES
AUGUST 2015
FDA
STRONGLY
ENCOURAGE TO
DISCONTINUE
USE OF THESE
PUMPS - MAY 2015
CHARLIE & CHRIS HOSPIRA
DRUG PUMP
FBI
Reverse engineer
proprietary software to
expose vulnerabilities
[Uconnect 8.4AN/RA4]
 Exploit weak
implementations of
network protocols
[D-BUS service port 6667]
 Modify firmware and re-
flash image to execute
arbitrary code
[TI OMAP-DM3730]
 Laterally move from the
compromised head unit
to the target CAN system
[CAN mcu Renesas v850]

OPEN SOURCE INTEROPERABILITY ROOT OF TRUST VIRTUALIZATION
BOEING
737/800
prpl Open Security Framework (prplSecurity™)
prplSecureBoot™
Root of Trust
prplSecureJTAG™
In-circuit Debug
prplInterVM™
Communications
prplHypervisor™
HW Virtualization
prplPUF™
Identity & Key
management
prplSecurity™ framework across hardware and software components
in both single tenant and multitenant use cases
IoT Multitenancy Requirements
Provider #1
Commercial Wi-Fi
public hotspot
1
Provider #2
Utility company
eMeter / IoT
21
Provider #1
Base services
LTE/DSL/Wi-Fi
3
Provider #3
pay per view
video streaming
?
Available
to next
provider
Multidomain Security
 New multitenant use cases – not
just trusted/not-trusted islands
 Strong security model perfectly
fits new multicore scenarios
 Hypervisor based – does not
require OS modifications
 Open source framework and
APIs – no royalties
 Reference framework open to
ecosystem partners development
WAN
prplHypervisor™
ISOLATED GUEST ISOLATED GUEST ISOLATED GUEST
prpSecureInterVM™ communications API
AVAILABLE
[Hot Plugin]
Commercial HotspotHome Network
Linux Kernel 3.x Linux Kernel 4.x
Heterogeneous Hardware SoC
prplSecurity™ Framework – Linux Application
prplSecurity™ Framework – IoT Application
Ethernet USB / UART
prplHypervisor™
ISOLATED GUEST #1 ISOLATED GUEST #2 ISOLATED GUEST #3
prpSecureInterVM™ communications API
USB / UART
Robotic Arm Control
Real time I/O
Key Management
[Intrinsic-ID]
TCP Listener
[Altran picoTCP]
Ethernet / SPI prplPUF™ API
IEEE SOCC Conference
Sep 2016, Seattle
prpl Foundation – Open source non-profit
About prpl Foundation
 Truly open community
 Heterogeneous open source
 Providing guidance
 Developing new standard APIs and
reference implementations
 Making advanced functionality as
portable as possible
 Working with regulators to protect
consumer choice and innovation
 Cross-collaboration initiatives
prpl Leadership
 Dan Artusi
VP and GM, Lantiq - an Intel Company
 Sherman Chen
Vice President Engineering, Broadcom
 Matt Grob
Executive VP and CTO, Qualcomm
 Jim Nicholas
EVP & MIPS B.U. GM, Imagination
 Art Swift
President, prpl Foundation
Takeaways
 IoT is already here but its security is
fundamentally broken - and could
soon result in human fatalities
 IoT security challenges include
proprietary software, connectivity,
firmware updates, lack of separation
 A new hardware security approach:
open source APIs, interoperable
protocols, secure boot, virtualization
Security, more than anything else,
will drive the next wave of IoT
adoption1
If the industry doesn’t fix the IoT
security issue, regulators will step in
– and this may hinder innovation2
prpl is leading the charge with
guidance, open source APIs and
reference implementations3
cesare@prplFoundation.org
http://prpl.works

More Related Content

What's hot

Ixia Customer Presentation
Ixia Customer PresentationIxia Customer Presentation
Ixia Customer Presentation
Gilles Lejeune
 

What's hot (10)

عينة عمل بالميكروسوفت باوربوينت
عينة عمل بالميكروسوفت باوربوينتعينة عمل بالميكروسوفت باوربوينت
عينة عمل بالميكروسوفت باوربوينت
 
Opinion: Why do so many new RAN players love Open RAN
Opinion: Why do so many new RAN players love Open RANOpinion: Why do so many new RAN players love Open RAN
Opinion: Why do so many new RAN players love Open RAN
 
Ixia Customer Presentation
Ixia Customer PresentationIxia Customer Presentation
Ixia Customer Presentation
 
Research Topics in Networking for PhD
Research Topics in Networking for PhDResearch Topics in Networking for PhD
Research Topics in Networking for PhD
 
Demystifying Software Defined Networking (SDN)
Demystifying Software Defined Networking (SDN)Demystifying Software Defined Networking (SDN)
Demystifying Software Defined Networking (SDN)
 
Cloud Native Driving 5G - COSCUP
Cloud Native Driving 5G - COSCUPCloud Native Driving 5G - COSCUP
Cloud Native Driving 5G - COSCUP
 
Tap Into the Health of Your Network
Tap Into the Health of Your NetworkTap Into the Health of Your Network
Tap Into the Health of Your Network
 
Sensor Networks Projects
Sensor Networks ProjectsSensor Networks Projects
Sensor Networks Projects
 
EENA2019: Track2 session4 _Study of use cases and communications involving Io...
EENA2019: Track2 session4 _Study of use cases and communications involving Io...EENA2019: Track2 session4 _Study of use cases and communications involving Io...
EENA2019: Track2 session4 _Study of use cases and communications involving Io...
 
Vtc keynote201110
Vtc keynote201110Vtc keynote201110
Vtc keynote201110
 

Similar to A New Hardware-Level Approach to Fix the Internet of Broken Things

An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...
An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...
An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...
Darren Carlson
 
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
Mullaiselvan Mohan
 
IntroductionThe capstone project is a �structured walkthrough� pen.pdf
IntroductionThe capstone project is a �structured walkthrough� pen.pdfIntroductionThe capstone project is a �structured walkthrough� pen.pdf
IntroductionThe capstone project is a �structured walkthrough� pen.pdf
fantasiatheoutofthef
 
Anomaly detection final
Anomaly detection finalAnomaly detection final
Anomaly detection final
Akshay Bansal
 

Similar to A New Hardware-Level Approach to Fix the Internet of Broken Things (20)

An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...
An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...
An Ad-hoc Smart Gateway Platform for the Web of Things (IEEE iThings 2013 Bes...
 
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
10 years in Network Protocol testing L2 L3 L4-L7 Tcl Python Manual and Automa...
 
Using Ansible Tower to implement security policies and telemetry streaming fo...
Using Ansible Tower to implement security policies and telemetry streaming fo...Using Ansible Tower to implement security policies and telemetry streaming fo...
Using Ansible Tower to implement security policies and telemetry streaming fo...
 
Io t standard_bis_arpanpal
Io t standard_bis_arpanpalIo t standard_bis_arpanpal
Io t standard_bis_arpanpal
 
IntroductionThe capstone project is a �structured walkthrough� pen.pdf
IntroductionThe capstone project is a �structured walkthrough� pen.pdfIntroductionThe capstone project is a �structured walkthrough� pen.pdf
IntroductionThe capstone project is a �structured walkthrough� pen.pdf
 
IRJET- Network Monitoring & Network Security
IRJET-  	  Network Monitoring & Network SecurityIRJET-  	  Network Monitoring & Network Security
IRJET- Network Monitoring & Network Security
 
Critical analysis of radar data signal de noising by implementation of haar w...
Critical analysis of radar data signal de noising by implementation of haar w...Critical analysis of radar data signal de noising by implementation of haar w...
Critical analysis of radar data signal de noising by implementation of haar w...
 
Profibus International and basics of Profibus and Profinet - Mark Freeman
Profibus International and basics of Profibus and Profinet - Mark FreemanProfibus International and basics of Profibus and Profinet - Mark Freeman
Profibus International and basics of Profibus and Profinet - Mark Freeman
 
Butler
ButlerButler
Butler
 
Introduction to NBL
Introduction to NBLIntroduction to NBL
Introduction to NBL
 
Anomaly detection final
Anomaly detection finalAnomaly detection final
Anomaly detection final
 
IRJET- Analysis of Forensics Tools in Cloud Environment
IRJET-  	  Analysis of Forensics Tools in Cloud EnvironmentIRJET-  	  Analysis of Forensics Tools in Cloud Environment
IRJET- Analysis of Forensics Tools in Cloud Environment
 
MANRS - Introduction to Internet Routing Security
MANRS - Introduction to Internet Routing SecurityMANRS - Introduction to Internet Routing Security
MANRS - Introduction to Internet Routing Security
 
Cisco Connect Halifax 2018 Simple IT
Cisco Connect Halifax 2018   Simple ITCisco Connect Halifax 2018   Simple IT
Cisco Connect Halifax 2018 Simple IT
 
Tapping Into the Health of Your Network
Tapping Into the Health of Your NetworkTapping Into the Health of Your Network
Tapping Into the Health of Your Network
 
IPv4 to IPv6 network transformation
IPv4 to IPv6 network transformationIPv4 to IPv6 network transformation
IPv4 to IPv6 network transformation
 
Chp11 infrastructure for ec
Chp11 infrastructure for ecChp11 infrastructure for ec
Chp11 infrastructure for ec
 
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk App for Stream for Enhanced Operational Intelligence from Wire DataSplunk App for Stream for Enhanced Operational Intelligence from Wire Data
Splunk App for Stream for Enhanced Operational Intelligence from Wire Data
 
A Deeper Look into Network Traffic Analysis using Wireshark.pdf
A Deeper Look into Network Traffic Analysis using Wireshark.pdfA Deeper Look into Network Traffic Analysis using Wireshark.pdf
A Deeper Look into Network Traffic Analysis using Wireshark.pdf
 
Network monitoring tools
Network monitoring toolsNetwork monitoring tools
Network monitoring tools
 

More from Hardway Hou

More from Hardway Hou (20)

商业计划书-翰鹏-201604
商业计划书-翰鹏-201604 商业计划书-翰鹏-201604
商业计划书-翰鹏-201604
 
Tiktok抖音,今日头条-商务合作方案
Tiktok抖音,今日头条-商务合作方案Tiktok抖音,今日头条-商务合作方案
Tiktok抖音,今日头条-商务合作方案
 
跳过私有云建设的“坑” 私有云建设经验教训以及IBM PMC2.0 简介
跳过私有云建设的“坑” 私有云建设经验教训以及IBM PMC2.0 简介跳过私有云建设的“坑” 私有云建设经验教训以及IBM PMC2.0 简介
跳过私有云建设的“坑” 私有云建设经验教训以及IBM PMC2.0 简介
 
混合云安全创新实践应用
混合云安全创新实践应用混合云安全创新实践应用
混合云安全创新实践应用
 
根据早期多云之旅获得的经验总结
根据早期多云之旅获得的经验总结根据早期多云之旅获得的经验总结
根据早期多云之旅获得的经验总结
 
好孩子企业互联网化--转型战略及系统架构
好孩子企业互联网化--转型战略及系统架构好孩子企业互联网化--转型战略及系统架构
好孩子企业互联网化--转型战略及系统架构
 
Trends and Practices of Cloud
Trends and Practices of CloudTrends and Practices of Cloud
Trends and Practices of Cloud
 
OpenStack Swift的性能调优
OpenStack Swift的性能调优OpenStack Swift的性能调优
OpenStack Swift的性能调优
 
Penetration testing the cloud - vlad gostom
Penetration testing the cloud - vlad gostomPenetration testing the cloud - vlad gostom
Penetration testing the cloud - vlad gostom
 
Lessons Learned from an early Multi-Cloud journey
Lessons Learned from an early Multi-Cloud journeyLessons Learned from an early Multi-Cloud journey
Lessons Learned from an early Multi-Cloud journey
 
How To Build A Stable And Robust Base For a “Cloud”
How To Build A Stable And Robust Base For a “Cloud”How To Build A Stable And Robust Base For a “Cloud”
How To Build A Stable And Robust Base For a “Cloud”
 
量子云:高性能云计算在影视行业应用
量子云:高性能云计算在影视行业应用量子云:高性能云计算在影视行业应用
量子云:高性能云计算在影视行业应用
 
迎接云计算大时代 - EasyStack 联合创始人兼CTO 刘国辉
迎接云计算大时代 - EasyStack 联合创始人兼CTO 刘国辉迎接云计算大时代 - EasyStack 联合创始人兼CTO 刘国辉
迎接云计算大时代 - EasyStack 联合创始人兼CTO 刘国辉
 
连接CONNECTION - 用连接突破数据中心时空限制
连接CONNECTION - 用连接突破数据中心时空限制连接CONNECTION - 用连接突破数据中心时空限制
连接CONNECTION - 用连接突破数据中心时空限制
 
浅谈架构升级
浅谈架构升级浅谈架构升级
浅谈架构升级
 
泛数据时代给各行业所带来的变革与机遇
泛数据时代给各行业所带来的变革与机遇泛数据时代给各行业所带来的变革与机遇
泛数据时代给各行业所带来的变革与机遇
 
数据让机器更智能
数据让机器更智能数据让机器更智能
数据让机器更智能
 
慧数据,联未来 -- 助力企业客户构建数据服务生态
慧数据,联未来 -- 助力企业客户构建数据服务生态慧数据,联未来 -- 助力企业客户构建数据服务生态
慧数据,联未来 -- 助力企业客户构建数据服务生态
 
构建企业私有云、开启服务新里程——基于Dcos的PAAS实践
构建企业私有云、开启服务新里程——基于Dcos的PAAS实践构建企业私有云、开启服务新里程——基于Dcos的PAAS实践
构建企业私有云、开启服务新里程——基于Dcos的PAAS实践
 
应用开发利器 IBM Bluemix平台云介绍
应用开发利器 IBM Bluemix平台云介绍应用开发利器 IBM Bluemix平台云介绍
应用开发利器 IBM Bluemix平台云介绍
 

Recently uploaded

( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
nilamkumrai
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Chandigarh Call girls 9053900678 Call girls in Chandigarh
 

Recently uploaded (20)

Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
Russian Call Girls in %(+971524965298  )#  Call Girls in DubaiRussian Call Girls in %(+971524965298  )#  Call Girls in Dubai
Russian Call Girls in %(+971524965298 )# Call Girls in Dubai
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
(INDIRA) Call Girl Pune Call Now 8250077686 Pune Escorts 24x7
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort ServiceEnjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
Enjoy Night⚡Call Girls Dlf City Phase 3 Gurgaon >༒8448380779 Escort Service
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Sarai Rohilla Escort Service Delhi N.C.R.
 
Dubai Call Girls Milky O525547819 Call Girls Dubai Soft Dating
Dubai Call Girls Milky O525547819 Call Girls Dubai Soft DatingDubai Call Girls Milky O525547819 Call Girls Dubai Soft Dating
Dubai Call Girls Milky O525547819 Call Girls Dubai Soft Dating
 
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Katraj ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Katraj ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
𓀤Call On 7877925207 𓀤 Ahmedguda Call Girls Hot Model With Sexy Bhabi Ready Fo...
 
VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...
VVIP Pune Call Girls Mohammadwadi WhatSapp Number 8005736733 With Elite Staff...
 
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
 
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
 
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
Low Sexy Call Girls In Mohali 9053900678 🥵Have Save And Good Place 🥵
 
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
Hire↠Young Call Girls in Tilak nagar (Delhi) ☎️ 9205541914 ☎️ Independent Esc...
 
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providersMoving Beyond Twitter/X and Facebook - Social Media for local news providers
Moving Beyond Twitter/X and Facebook - Social Media for local news providers
 

A New Hardware-Level Approach to Fix the Internet of Broken Things

  • 1. A New Hardware-Level Approach to Fix the Internet of Broken Things C e s a r e G a r l a t i , C h i e f S e c u r i t y S t r a t e g i s t , p r p l F o u n d a t i o n
  • 2. A New Hardware-Level Approach to Fix the Internet of Broken Things Cloud Connect China 2016 Cesare Garlati, Chief Security Strategist, prpl Foundation
  • 3. Securing the Internet of broken things Source: Remote Exploitation of an Unaltered Passenger Vehicle, Dr. Charlie Miller and Chris Valasek, August 2015 1.4M FIAT CHRYSLER RECALLS 1.4 MILLION VEHICLES AUGUST 2015 FDA STRONGLY ENCOURAGE TO DISCONTINUE USE OF THESE PUMPS - MAY 2015 CHARLIE & CHRIS HOSPIRA DRUG PUMP FBI Reverse engineer proprietary software to expose vulnerabilities [Uconnect 8.4AN/RA4]  Exploit weak implementations of network protocols [D-BUS service port 6667]  Modify firmware and re- flash image to execute arbitrary code [TI OMAP-DM3730]  Laterally move from the compromised head unit to the target CAN system [CAN mcu Renesas v850]  OPEN SOURCE INTEROPERABILITY ROOT OF TRUST VIRTUALIZATION BOEING 737/800
  • 4. prpl Open Security Framework (prplSecurity™) prplSecureBoot™ Root of Trust prplSecureJTAG™ In-circuit Debug prplInterVM™ Communications prplHypervisor™ HW Virtualization prplPUF™ Identity & Key management prplSecurity™ framework across hardware and software components in both single tenant and multitenant use cases
  • 5. IoT Multitenancy Requirements Provider #1 Commercial Wi-Fi public hotspot 1 Provider #2 Utility company eMeter / IoT 21 Provider #1 Base services LTE/DSL/Wi-Fi 3 Provider #3 pay per view video streaming ? Available to next provider
  • 6. Multidomain Security  New multitenant use cases – not just trusted/not-trusted islands  Strong security model perfectly fits new multicore scenarios  Hypervisor based – does not require OS modifications  Open source framework and APIs – no royalties  Reference framework open to ecosystem partners development WAN prplHypervisor™ ISOLATED GUEST ISOLATED GUEST ISOLATED GUEST prpSecureInterVM™ communications API AVAILABLE [Hot Plugin] Commercial HotspotHome Network Linux Kernel 3.x Linux Kernel 4.x Heterogeneous Hardware SoC prplSecurity™ Framework – Linux Application
  • 7. prplSecurity™ Framework – IoT Application Ethernet USB / UART prplHypervisor™ ISOLATED GUEST #1 ISOLATED GUEST #2 ISOLATED GUEST #3 prpSecureInterVM™ communications API USB / UART Robotic Arm Control Real time I/O Key Management [Intrinsic-ID] TCP Listener [Altran picoTCP] Ethernet / SPI prplPUF™ API IEEE SOCC Conference Sep 2016, Seattle
  • 8. prpl Foundation – Open source non-profit About prpl Foundation  Truly open community  Heterogeneous open source  Providing guidance  Developing new standard APIs and reference implementations  Making advanced functionality as portable as possible  Working with regulators to protect consumer choice and innovation  Cross-collaboration initiatives prpl Leadership  Dan Artusi VP and GM, Lantiq - an Intel Company  Sherman Chen Vice President Engineering, Broadcom  Matt Grob Executive VP and CTO, Qualcomm  Jim Nicholas EVP & MIPS B.U. GM, Imagination  Art Swift President, prpl Foundation
  • 9. Takeaways  IoT is already here but its security is fundamentally broken - and could soon result in human fatalities  IoT security challenges include proprietary software, connectivity, firmware updates, lack of separation  A new hardware security approach: open source APIs, interoperable protocols, secure boot, virtualization Security, more than anything else, will drive the next wave of IoT adoption1 If the industry doesn’t fix the IoT security issue, regulators will step in – and this may hinder innovation2 prpl is leading the charge with guidance, open source APIs and reference implementations3