Longer Chip Lifecycles Increase Security Threat


The longer chips and electronic systems remain in use, the more they will need to be refreshed with software and firmware updates. That creates a whole new level of security risks, ranging from over-the-air intercepts to compromised supply chains. These problems have been escalating as more devices are connected to the Internet and to each other, but it's particularly worrisome when it invol... » read more

SolarWinds Attack Is A Cautionary Tale For Hardware And Its Supply Chain


The recent SolarWinds hacking incident that left many Fortune-500 companies and US government networks exposed is an interesting cautionary tale for unchecked software and hardware supply chain security vulnerabilities. The highly sophisticated software supply chain attack occurred in the SolarWinds Orion IT monitoring system. This system, used by over 33,000 companies, monitors performance acr... » read more

IoT Cybersecurity Improvement Act of 2020


The "IoT Cybersecurity Improvement Act of 2020" became a U.S. law on 12/4/2020.   The legislation was passed by unanimous consent by the Senate and the House of Representatives. Congress.Gov states: "This bill requires the National Institute of Standards and Technology (NIST) and the Office of Management and Budget (OMB) to take specified steps to increase cybersecurity for Internet of ... » read more

Security Breaches And The Defensive Mindset


Over the Christmas break, the biggest security breach ever came to light. It is assumed to be instigated by a foreign entity. The breach is known mostly as SolarWinds. SolarWinds produces network management software called Orion that is used by...well, almost everyone. The attackers inserted a backdoor into an Orion software update. You know how the operating system on your PC or Mac gets autom... » read more

The Key is Left under the Mat: On the Inappropriate Security Assumption of Logic Locking Schemes


Abstract: "Logic locking has been proposed as an obfuscation technique to protect outsourced IC designs from IP piracy by untrusted entities in the design and fabrication process. In this case, the netlist is locked by adding extra key-gates, and will be unlocked only if a correct key is applied to the key-gates. The key is assumed to be written into a non-volatile memory after the fabricati... » read more

Manufacturing Bits: Dec. 7


Cybersecurity for manufacturing The University of Texas at San Antonio (UTSA) has launched a center to address cybersecurity issues in the U.S. manufacturing sector. The center, called the Cybersecurity Manufacturing Innovation Institute (CyManII), is a $111 million public-private partnership. As part of the effort, UTSA will enter into a five-year corporative agreement with the U.S. Depart... » read more

Safeguarding Automotive Electronics


Modern automobiles can have up to 100 Electronic Control Units (ECUs) depending on their class, make, and model, with the number of ECUs rising even higher in the case of electric vehicles. An ECU is an embedded system in the car’s electronics. They are used to control all the vehicle's functions, including engine, powertrain, transmission, brakes, suspension, dashboard, entertainment system ... » read more

Effective Configuration Of Security Tools


To do a job well, you need the right tools. But it’s just as important—perhaps even more so—to use those tools correctly. A hammer will make things worse in your construction project if you’re trying to use it as a screwdriver or a drill. The same is true in software development. The intricacies of coding and the fact that it’s done by humans means that throughout the software deve... » read more

Security Gaps In Open Source Hardware And AI


Semiconductor Engineering sat down to discuss security risks across multiple market segments with Helena Handschuh, security technologies fellow at Rambus; Mike Borza, principal security technologist for the Solutions Group at Synopsys; Steve Carlson, director of aerospace and defense solutions at Cadence; Alric Althoff, senior hardware security engineer at Tortuga Logic; and Joe Kiniry, princi... » read more

Establishing A Special Interest Group On Common Hardware Weaknesses


It seems like almost every week yet another hardware security vulnerability is announced. Just last week a team of researchers disclosed a new attack called “Platypus”, an acronym for "Power Leakage Attacks: Targeting Your Protected User Secrets.” This is another attack exploiting the simple fact that hardware sits below the conventional security abstractions and finding a vulnerability i... » read more

← Older posts Newer posts →