Dark Light

Arm’s SystemReady 2.0 to Secure IoT Devices Leave a comment

[ad_1]

//php echo do_shortcode(‘[responsivevoice_button voice=”US English Male” buttontext=”Listen to Post”]’) ?>

For OEMs developing connected devices, ensuring those will be secure over a long period is one of the most important considerations. On a connected computing device, such as a laptop, server, smartphone or tablet, receiving software updates, including security patches, is a regular thing. This is different for the billions of IoT devices deployed worldwide. Arm’s SystemReady is a compliance certification program based on hardware and firmware standards: Base System Architecture (BSA) and Base Boot Requirements (BBR) specifications, plus a selection of supplements. This ensures that subsequent layers of software also “just work.” SystemReady first launched in 2020, has achieved over 100 certifications. It spans areas from infrastructure to IoT, reducing ownership costs while accelerating market time.

A critical factor for adoption is regulation. In Europe, upcoming legislation like the proposed Cyber Resilience Act will pay closer attention to essential functionality, such as secure boot and mandatory software updates after devices ship. When the proposed regulation enters into force, software and products connected to the internet will bear the CE marking to indicate they comply with the new standards.

We had the opportunity to talk to Paul Williamson, Arm’s SVP & GM for the IoT Line of Business, about SystemReady. He shared the essential benefits of the program and argued why it is crucial to ensure continuous security updates to all connected devices out there.

Arm’s Paul Williamson.
Arm’s Paul Williamson

“What we’re trying to do is focus on the non-differentiating elements of the software builds and bring a consistent approach so that each time somebody wants to integrate a software, an operating system onto an Arm-based device, there’s less overhead work, less custom board support to be developed, and it frees up time to focus on the innovation and the new devices and capabilities that the system provides,” Williamson said.

“It is an initiative that’s been running for a little while now,” he added. “We’ve developed a range of variants of SystemReady that cover different classes of devices, so devices with different target applications from large-scale cloud compute workstations down to IoT embedded devices running Micro-Linux and other Linux builds like Yoct, OpenWRT or Debian Fedora.”

Currently, SystemReady applies to a broad set of devices initially in the data center server, edge and high-performance IoT ecosystems. The program includes a Security Interface Extension that addresses OS distributions’ requirements for standard security interfaces. There are minimum hardware requirements for implementing SystemReady, but the system must be able to receive and execute software, Williamson said.

SystemReady requirements.
SystemReady requirements (Source: Arm)

“Things like the adoption of a device tree for boot in the Linux corner ensures that you separately define the hardware capabilities of the platform from the operating system so that you’re not having to create a single, fully bundled image of the operating system and target a different build for every device, which makes software maintenance very difficult,” Williamson said.

“While Arm puts together this overall sort of guideline, if you like, in what SystemReady provides, and also a sort of conformance testing to make sure that the guidelines have been met in the form of certification, we don’t specify the performance or the capabilities of the device,” he added.

Matter and the interoperability of connected devices

New initiatives, such as the Matter protocol for the smart home, help provide essential security and interoperability between different systems but still need to resolve the need for regular updates.

Regarding Matter, Williamson praised the initiative as a way for smart-home devices to communicate and interact with each other but warned that the home network’s security is still at risk.

“SystemReady focuses on effectively solving problems for the people who are developing and maintaining software on devices, and so it’s about how I run an operating system and keep it secure for its lifetime,” he said.

“Matter is very much a sort of data-level protocol to allow the exchange of information between different devices in the home and their different capabilities,” he added. “So they’re perfectly complementary. You could run a Matter stack on a SystemReady solution and handle the firmware update using the data descriptors in Matter, but know that you’re doing that securely because you have under the hood a SystemReady device that can securely update its operating system.”

One of the critical benefits of SystemReady certification is to ensure that connected devices will continue to be secured after a long time deployed in the field.

In the new SystemReady IR2.0, the focus has been on providing better long-term compatibility between platforms and OS so that new OS versions do not break on older platforms. It also adds support for secure firmware over-the-air updates and Unified Extensible Firmware Interface (UEFI) secure boot.

Post-quantum cryptography

We spoke to Williamson about the kind of connected devices that, after being installed, will continue to operate for decades. And then we asked him about post-quantum cryptography and how this could be implemented in today’s devices, especially the ones with limited memory and processing capabilities.

“I think post-quantum crypto, our partners implement crypto in a number of ways,” Williamson said. “Sometimes with dedicated hardware accelerators, which do give you a lower memory footprint and a lower execution footprint typically, but with the cost of being rigid in hardware, versus others who will take the approach of using either a mixture of software and hardware or a pure software approach using our CPUs for execution, and our CPUs get more efficient at doing these kinds of algorithms with some of the later extensions like the inclusion of better instructions into the end devices. But we don’t actually take a position on specifying the specific cryptography used in communication standards. We look to make sure that the devices are secure and that they are capable of executing the required cryptography standards that are selected.

“SystemReady is focusing on effectively solving problems for the people who are developing and maintaining software on devices,” he added.

[ad_2]

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *