Loading...

Daily news and top headlines for electronic OEM design professionals

FREE Email Newsletter View Sample

The Main Circuit

Secure Mobile Hardware is Priceless

Must-read news, features and analysis for electronic OEM design pros - Sign up now!

Share:

E-mail:

Print:

Bookmark:

RSS:

[-] Text [+]

Featured In: Newsletters | The Main Circuit

By Linh Hong, Kilopass Technology | Thursday, August 19, 2010

Double-click any word to search

Highlight any phrase & click HotSearch

Loading...
With smart phones accounting for an increasing share of the mobile handheld market, more services and applications are being added, including premium TV and games, mobile banking, e-commerce, and even airline check-ins. With so much of one’s private data -- such as credit and debit card numbers -- stored on the mobile device, the mobile handheld must become a highly secure system to gain adoption of the new services and applications. The smart phone must have hardware and software security to protect against malware and reduce fraud, data theft, and theft of service.

On the hardware side, an essential security component in the subscriber identity module (SIM), baseband, and application processor integrated circuits is an electronic hiding place for secure boot code and keys. From digital rights management (DRM) to mobile TV applications, secure boot is required to prevent modification or replacement of boot images, and keys are required for different cryptography standards including public and symmetric keys. Today, non-volatile memory (NVM) including EEPROM, Flash, electrical fuse, and antifuse is used as the storage element in consumer products like set-top boxes, DTV and mobile handsets. But with increased smart phone security requirements, from e-commerce to mobile banking, not all NVM technologies used today will be viable in the future.

Hardware security in smart phones is driven by two different entities: the service providers and the handset makers. Service providers drive the requirements for SIM cards, while handset makers drive the requirements for the baseband and applications processors. Today, hardware security to meet mobile banking and premium TV requirements exists in the SIM card more so than in baseband and applications processors. In fact, the SIM card used in mobility devices is similar to that being used in banking smart cards; they both contain integrated circuits with NVM, a processing unit, security components, and I/Os. Smart cards for banking must comply with a common criteria standard of at least the evaluation assurance level 5 (EAL5), while SIM is much less rigid. It is natural for mobile SIM applications to adopt banking smart card standards to enable premium TV or mobile banking. Given that VISA and MasterCard have adopted it already, they will likely adopt it for mobile banking, and premium TV providers could easily follow. The challenge will be to support the performance required. Authenticating a pin and storing small amounts of banking data is much easier than decrypting obfuscated data containing audio and video. So, it may not be cost-effective to implement faster processors in SIM integrated circuits.

Although SIM cards may quickly transition to a higher level of secure hardware due to the smartcard platform used, the baseband and applications processors have the upper hand in computing power needed for premium TV or games. Basebands and application processors are implemented in bleeding-edge process nodes because of the benefits of performance and power. But the level of hardware security cannot match what is in a smartcard, due to cost. Something as simple as shielding the die to make it more difficult for destructive attacks will add another $200K to the cost of masks and as much as 10% to the die cost. As a result, other methods must be deployed to ensure a trusted environment for mobile applications. Hardware crypto engines are also integrated as a root of trust to enable secure boot and storage of keys for authentication, selective access and/or denial of specific services. But will this be sufficient for mobile banking or premium TV? Maybe for premium TV, given that multimedia processors in set-top boxes implement conditional access with a similar hardware platform with crypto engines and a root of trust where keys and identities are stored in an NVM. The same scheme is likely to be adopted by VISA or MasterCard for mobile banking as well, if the root of trust portion has been proven to meet the standards for banking smart cards today. 

Figure 1: Comparison of non-volatile memory technology for mobile security applications

As noted earlier, not all NVM currently used in the set-top boxes or DTV will be viable as the root of trust in next-generation smart phones, given the elevated level of security required--especially for mobile banking. Electrical fuses are not practical because they can be hacked so easily; their bitcell of 50um^2 is visible through a microscope. EEPROM and Flash are possible candidates with their flexibility and security, and are being used in smart cards today. But given that today’s baseband and application processors are already in production at 65 nm and 40 nm, EEPROM and Flash need to be eliminated because they are only available at 90nm and above. Infineon and TSMC announced a year ago they will jointly develop 65nm eFlash; however, it will likely take another two to three years before it is ready for mass production, given the historical track record of enabling eFlash in the pure play foundry. By then, it will be too late for baseband and application processors.

Antifuse technology has been widely adopted in the consumer market for HDCP, DTCP, and CA key standards as well as secure flash controllers to prevent the backdoor entry to the integrated circuits. Antifuse technology can be implemented in bleeding-edge processes such at 28 HKMG and is cost effective due to its small footprint and low active power. It is a good fit as the electronic hiding place in next-generation smart phones. It will need to be validated through the common criteria protection profile to meet mobile banking needs, but there is not a technology barrier to prevent meeting the criteria standard of at least EAL5. Recently, Kilopass, a pioneer of logic antifuse NVM released Gusto, a higher capacity (up to 4Mb), smaller form factor (0.8 mm^2/Mb), faster (20n s), and lower power (0.3 mW/MHz at 32 bits) one-time programmable memory (OTP). With the availability of a higher-capacity solution such as this, secure code storage for mobile applications is now conceivable, adding another dimension to enable a total root of trust from keys to boot code.

The smart phone will become ubiquitous in another five years and will likely change the way commerce and banking is done is today. It will open up endless services and may eliminate our credit cards, checkbooks, and currency. Adoption will begin only when the root of trust is validated. Today, antifuse technology is the only viable solution to contain the root of trust for next-generation smart phones.

Join the Discussion
Rate Article:  Average 0 out of 5
register or log in to comment on this article!

0 Comments

Add Comment

Text Only 2000 character limit

Page 1 of 1

Dungeons and Dragons Dice Gauntlet
Dungeons and Dragons Dice Gauntlet

Feb 3

The D&D bracer is a fairly quick, fun, nerdy LilyPad project. The final product is a wearable bracer with a display that will randomly generate numbers between 1 and 4, 6, 8, 10, 12, 20, or 100 in response to arm movement, so it can effectively replace all of the dice in your bag for a D&D session.

Sustainable?
Sustainable?

Feb 2

I'd like some genius to define sustainable. Could we count something that we can keep doing for 100 billion years - beyond the death of the Universe as we currently understand such things - as sustainable? How about a billion years?

TopicStarterLast Post
Digital watch voice recorderEdipo FerrariOct 1
HolidaysJason LombergMar 3
iPhone OwnerJason LombergNov 17
Video Game ViolenceJason LombergJan 6
Global Warming/Climate ChangeJason LombergAug 11
3D TechJason LombergNov 17
Medical ElectronicsJason LombergNov 17
The Incandescent BanJason LombergNov 17
Video of the Day


Free Electronic OEM Design
Industry Subscriptions

Magazine

ECN magazine

Newsletters

newsletters

Sign up now


Archived Issues

Top Stories and Headlines
EVERY DAY!

FREE Email Newsletter