1/47
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Smart Cards(Chip cards)
- By the end of 2006 SCs were common in Western Europe
- Some applications include voting in Swedan(Non-repudiation device), phones with smart cards exported to the US
- British Air's oyster card was used for trains and planes for connections.
- In 2006, ~27M contactless cards were in circulation in US,
the number is estimated to top 100M by 2020
- e.g., homeland security has required the port workers to have
smart ID cards (Jan, 2007)
- Entertainment: Most DSS dishes in the U.S. have smart cards
VSLI (Very Large-Scale Integration)
- 100K-1M components per chip
- A complex logical circuit with billions of transitors
ULSI (Ultra Large Scale Integration)
- More than 1M components per chip
- Trillons of transistors
- Used for GPUs, chips
Integrated Circuit Package
Single package containing multiple electronic components such as a CPU.
RFID (radio frequency identification)
Uses a chip in a tag or label to store information, and information is transmitted from, or written to, the tag or label when the chip is exposed to the correct frequency of radio waves. Used for tracking and iding animals, products, people, etc. Radio waves are sinusoidal waves
RFID parts
- Integrated Circuit to store and process info, modulating and demodulating a radio freq(rf) signal and more
- An antenna for receiving and transmitting
- Some are active (battery-powered), while others are passive
Business Model

RFID applications
- Inventory Control Container / Pallet Tracking
- ID Badges and Access Control
- Fleet Maintenance Equipment/Personnel Tracking in
Hospitals
- Parking Lot Access and Control
- Car Tracking in Rental Lots
- Product Tracking through Manufacturing and
Assembly
Cryptography
- The science that studies encryption, which is the hiding of messages so that only the sender and receiver can read them.
- Crypto(secret)+graph(writing)
- Science/math of locks and keys
- Underlying every security mechanism
- HW-based secret is new
HW Threats chart(Slide 9-12)
IP Vendors: IP Trust
System Integrator: IP Piracy System Trust
Manufacturer: IC Trust, IC Piracy, Secure Manufacturing Test

AES(Advanced Encryption Standard)
-Asymmetric encryption standard?
- Recent form of cryptography
Computer Security
- Hardware and software
- Input/output modules
- Data
- Storage
- Network interconnections
Embedded System
- A computer system with a dedicated function within a larger electrical or mechanical system.
- Security is challenging due to size, power, and environmental constraints, as well as the other system aspects.
- Can have its own microprocessor, memory, network capabilities and I/O
Secure
- Asset must have a value, no set def
- Sophisticated and no methods for protection exist
Cycle for securing a system
1) Predict potential breaches
2) Consider controls or countermeasures
3)Identify a breach or wait for it
4) Once identified work out a protected system
Computer Security
- No matter the sophistication of the system, simple breaches are still possible
- A computer system has data, storage media, storage media, human interactions
- Many breaches come from social engineering(people)
HW/SW Security
- Manufactured ICs are obscure
- HW is the platform running SW, storage and data
- Tampering can be conducted at many levels
- Easy to modify because of its physical nature
Vulnerability
A flaw or weakness that allows a threat agent to bypass security.
Threat
Set of circumstances with the potential to cause loss or harm
Attack
Human exploiting a system's vulnerability.
Computer security aspects
- Confidentiality: the related assets are only accessed by authorized parties
- Integrity: the asset is only modified by authorized parties
- Availability: the asset is accessible to authorized parties at appropriate times
Hardware Vulnerabilities
- Phys attack
- Trojan Horse(HW, SW)
-IP Piracy/IC Piracy and counterfeit
- Backdoors, Often left on purpose
- EX: For testing(default account), web shell(SSH, SFIP is a good example)
-Non-Tamper Resistant
- Backtrack-> Kali-Linux(Scans for vulnerabilities) Good to use in a sandbox like VirtualBox or VMware to reduce system compromisation
Adversaries(Individuals, group, gov)
- Pirate IPs
- Trojan horses
- Reverse engineer ICS
- Spying by exploiting IC vulnerabilities
Adversaries(System integrators, farbrication facilities, counterfeit)
System integrators
Pirating the IPs
Fabrication facilities
Pirating the IPs & ICs
Counterfeiting Parties
Recycling, cloned, etc.
Hardware Controls
- Hardware implementations of encryptions
= Encryption and scrambling: Transmitting important messages are scrambled/Permutation/transposition
- Design or physical lock
- Devices to verify user
- Hide signatures in design files
- Intrusion detection
- Hardware board limit memory access
- Tamper-resistant
- Policies and procedures
Embedded Systems security
- Security processing adds overhead
- Size, space, power, volume constraints in harsh environments
- May affect the main job
- When designing security think about cost, power, area
Secret
- Underlying most security mechanisms or protocols
- Lock and keys
- Passwords
- Hidden signs and
procedures
- Physically hidden
Cryptography History, Pencil and paper era
- Over 2000 years old and predates computers, electronics or any technology.
Early cryptography relied on methods to simply scramble text - otherwise known as cipher.
- 513 B.C. Histiaeus of Miletus shaved his slave's head and tattooed a message on it
Caesar's cipher: Shift each letter of the alphabet by a fixed amount, easy to break
Cryptoquote
- Plain text to Ciphertext
- Permutations of 26 letters, substitution cipher
- Can be broken with dictionary and frequencies
Cryptography - Mechanical Era
- 1900 is when people realized the math and stat roots
- Germans developed the Enigma machine, Tunny to encrypt messages
- Some Polish mathematicians obtained one, sold it to Britain
- Over 10,000 worked to solve it, helped to interpet German's messages during wars and shorten it by a year
- ks: Keystream from a pseudo random # generator
- p: Plain text
- c: Cipher
- XOR: Or statement
- Key stream or statement with p to make cipher c (𝑐 = 𝑝 ⊕ 𝑘𝑠)
Tunny
- German made
- Use a pseudorandom number gen, a seed to make a keystream("ks")
- Key stream XOR'd with plain text to produce cipher(add equ here)
- Solved by cryptographer at Bletchley park in 1942
Shannon's Information Theory
Evaluates the effectiveness of communications systems. Elements include:
- Signal-to-noise (S/N) ratio
-Channel capacity (max information transmitted
with minimal error)
-Entropy (amount of energy, code, or bits needed
for storage or communication of one
signal)
- More valuables you have, the more complex you can get
- Let's say x and y is 0 or 1. So that means 2*2 = 4 possibilities; more variables mean an exponential increase
- Shannon created 1-time pad and theoretical analysis of code
- Started in 1970s
- Developed for banks and military systems(GPS is an example, so is the internet)
- NIST developed a set of standards for banks called DES, now standard is AES
Design Process - Old Way(Photo on slide 13)
- DFT - Design For Test
- GDSII - Graphic Database
System II
- GL - Gate Level
- RTL - Register Transfer
Level
- STA - Static Timing
Analysis

Design process - New Way(Slide 14)

Counterfeiting(Slide 18)

IC Counterfeiting
- Most prevalent attack today
• Unauthorized production
of wafers
• It is estimated that
this is costing
semiconductor industry
several billion dollars per
year
IC(Integrated circuit) Recycling(Slide 20)
1) Recycling center
2) Printed circut boards(PCBS) taken off electronic systems
3) ICs extracted from PCBS
4) Refine the recycled ICS
5) Resell them as new
6) The recycled ICs may be used in critical applications like helicopters and may fail
- Are often identical to an unrecycled IC in looks, function, and specification
- More ewaste as consumers use electronics for shorter times
Supply Chain Vulnerabilities(Slide 21)

Chen Jin and piracy
• In 2000 he finished his Ph.D. in computer
engineering at UT Austin
• He went back to China, first to Motorola research and then to Jiaotong University as a faculty
• In 2003, he supervised a team that created one of
China's first homegrown DSP ICs
• Was named one of China's brightest young
scientists, funded his own lab, got a huge grant from
the government
• In 2006, it was revealed that he faked the chip, stealing the design from Texas Instruments!
The Athens Affair
• In March 8, 2005, Costas Tsalikidis, a 38-year-old
Engineer working for Vodafone Greece committed
suicide - linked to the scandal!
• The next day, the prime minister got notified that his
cell phone - and those of many other high-ranking
officials - were hacked!
• Earlier in Jan, investigators had found rogue software
installed on Vodafone Greece by parties unknown
• The scheme did not depend on the wireless nature
• A breach in keeping keys in a file - Vodafone was fined
€76 million in December 2006!
Intellectual Property
A product of the intellect, such as an expressed idea or concept, that has commercial value.
Patent
When you register your invention with the
government, you gain the legal right to exclude anyone
else from manufacturing or marketing it.
Trademarks
A a name, phrase, sound or
symbol used in association with services or products.
Copyrights
Laws protect written or artistic expressions fixed in a tangible medium
Trade secrets
A formula, pattern, device or compilation of
data that grants the user an advantage over competitors.
Cryptography: Modern Era
• First major theoretical development in crypto
after WWII was Shannon's Information Theory
• Shannon introduced the one-time pad and
presented theoretical analysis of the code
• The modern era really started around 1970s
• The development was mainly driven by banks and
military system requirements
• NIST developed a set of standards for the banks,
- DES: Data Encryption Standard
Security Requirements
- Basic functions
- Tamper resistance
- User Identification
- Content Security
- Secure Network Access
- Availability
- Secure Storage
Threats to messages
Interception: Confidentiality
Interruption Blocking messages: Availability
Modification and fabrication: Integrity