Page 34 - EE Times Europe Magazine | February 2020
P. 34

32 EE|Times EUROPE
            Memory with Integrated Secure Element Ensures More Data Security



            standard data memory offers a technically                                 interesting regarding data traffi c in elec-
            elegant solution. Tap-proof mobile phones,                                trical car systems. The communication of
            bodycams, and counterfeit-proof cash                                      electronic control units (ECUs) via bus sys-
            registers are already secured with this type                              tems could be encrypted if, for example, an
            of card. The simplicity of distribution and                               embedded multimedia controller (eMMC)
            content loading will not suffer. A high-res-                              with Secure Element serves as a Trusted
            olution map update would be a stress test                                 Platform Module at the nodes. Thanks
            — performance- and cost-wise — for mobile                                 to this authentication feature, the risk of
            data plans.  ome loading or simple drop-in                                tampering with in-vehicle communications
            replacement by a mechanic guarantees the                                  can be averted.
            required simplicity.                                                        In the car, there are two categories of
                                                The communication of ECUs via bus     functional safety  security-related and
            AN APPROACH WITH POTENTIAL          systems could be encrypted if, for example,   non-security related. This distinction
            Using fl ash memory modules with Secure   an eMMC with Secure Element serves as   is generally made so that, for example,
            Element offers direct benefi ts such as   a Trusted Platform Module at the nodes.   the infotainment system has no access to
            gaining control of navigation system   (Image: Swissbit)                  safety-related systems on the platform. Yet
            data and being able to ensure compliance                                  even for the non-safety related elements,
            with license terms. Yet additionally, this                                the option to provide for fl exible and sus-
            approach offers a broad range of applica-                                 tainable cybersecurity is required because
            tion scenarios relating to data protection                                the life cycle of cars can easily exceed 10
            and cybersecurity in cars. Infotainment                                   years. By then, many as-yet-not-obvious
            systems are platforms that offer a base                                   requirements will need to be fulfi lled,
            for further communications services.                                      such as toll collection, billing of e-charges,
            These systems are becoming increasingly                                   chargeable value-added media services,
            important as an interface to ICT devices                                  subscriptions for updates of navigation
            and the internet. When offering charge-                                   map data, and much more. The added value
            able services for this, receiving valuable                                of the infotainment system will increase as
            media content, paying toll charges, or                                    it performs increasingly more important
            supporting e-charging use cases, the                                      tasks. On the other hand, automotive IT
            issue of unique identity and, thus, a                                     systems will be exposed to increasingly
            secure authentication entity arises again.                                more sophisticated attacks over time.
             ere, memory cards with an integrated                                       For security reasons and as a pre-
            SmartCard offer the ideal solution as well   A secure replaceable storage medium, such   caution, a fl exible, replaceable Secure
            — especially because they can be securely   as the SD Memory Card from Swissbit,   Element in a memory card should be
            paired with the vehicle and replaced so   would be a suitable solution to keep the se-  provided for the protection of future
            easily when necessary. Careful consider-  curity of an infotainment system up to date   business. The British Standards Insti-
            ation should be taken before abandoning   during the life cycle of a car. (Image: Swissbit)  tution (BSI) requires the consistent
            an SD card reader as an interface on                                      application of state-of-the-art technology,
            infotainment devices. Using the relevant                                  which cannot be achieved for security
            cards, new functions can be retrofi tted and continuously secured at   solutions that are several years old and especially purely based on
            the highest cryptographical level.                    software security, which offers the required fl exibility but never the
                                                                  required long-term security. Therefore, it is advisable to maintain the
            SECURITY AS A SAFETY ASPECT                           option of a replaceable hardware security module. Another benefi t in
            In recent years, increasingly greater networking within and outside the   addition to easy modifi cation and retrofi tting  Different software-de-
            car — for instance, Car2Car Communication — has made security in the   pendent confi gurations of the same model are easy to manage. All
            sense of defending cyberattacks a subject for debate, mainly against the   variants are confi gured, and with the help of Secure Element on the
            background of possible effects on functional security. The suggestion   memory card, the ones purchased by the customer are activated — an
            to use memory modules with Secure Element, introduced here, is also   effective way to simplify the variant diversity in production. And
                                                                  when deciding between a soldered and removable fl ash memory, the
                                                                  negative effect on the durability of the NAND chips in the memory
                                                                  modules, caused by a combination of frequent access and challenging
                                                                  thermal conditions in the car, should be considered. This means that
                                                                  for memory cards that cannot be replaced by a mechanic, signifi cantly
                                                                  more expensive solutions need to be found.
                                                                    The protection of maps using memory cards with a security feature
                                                                  is just one example of an application in which the combination of
                                                                  memory card and SmartCard allows for a higher degree of control
                                                                  and security. When edging toward information and communication
                                                                  technology and consumer electronics, other security considerations,
                                                                  development cycles, and market mechanisms prevail other than in
                                                                  automobile manufacturing  thus, the use of a replaceable standard
                                                                  element offers the option to create a high level of security using
                                                                  hardware-based cryptography while remaining permanently fl exible
            (Image: Fotolia)                                      regarding the integration of additional services. ■

                                                                                       www.eetimes.eu | FEBRUARY 2020ww.eetimes.eu | FEBRUARY 2020
            FEBRUARY 2020 | www.eetimes.euY 2020 | www.eetimes.euY 2020 | www.eetimes.eu
            FEBRUARFEBRUAR                                                             w
   29   30   31   32   33   34   35   36   37   38   39