Home | About Ferret
Australia's Manufacturing and Industrial Directory
Submit Your Listing
Newsletter Sign Up
Search
missing search term
Dominion Electronics

Dominion Electronics present Digi International’s insights on embedded systems security

By Dominion Electronics
Got a Question for Dominion Electronics?
Enquire Now
Visit Website
Dominion Electronics
Tel: 02 9906 6988
Fax: 02 9906 7145
Unit 13
Artamon
NSW 2064
Visit Website Enquire Now
Update these details
Close

Timothy Stapko, Lead Software Engineer and Project Manager, Digi International, offers tips on embedded systems security. Dominion Electronics are distributors of Digi International.

There are a large number of security packages available, and an embedded engineer new to security may only know of security as encryption or virus protection. While encryption is a tool used for security and virus scanners technically provide security, neither one likely provides what is needed. These days security is integrated into many applications and the packages that users need are usually dictated by what their applications will interface with. If users’ application is web-based, it probably will use SSL/TLS (Secure Sockets Layer, also known as Transport Layer Security). Other applications use technologies like IPSEC (Internet Protocol Security) or CCMP (WPA2 Wi-Fi encryption). Knowing what the acronyms mean is not as important as knowing which protocols users need to support.

Depending on the application, implementing a security package for an application may be as simple as running an executable with security enabled. For example, if users are running embedded Linux or Windows CE, there are probably applications that provide a lot of the security they need, like an SSH (Secure Shell) client. If binaries are not available, then there may be source code available. Open-source packages like OpenSSL and OpenSSH are considered among the best implementations of those security protocols available that are also free to use. Users should avoid implementing their own security protocol. Unless users are cryptography experts, chances are their implementation will be vulnerable.

Once users have implemented their application and added all their security protocols, it is natural to ask how secure the result is. The purpose of security is to make the cost of breaking the security greater than the value of the gain for the attacker. Modern cryptography relies on mathematics that would take thousands of years to work out using modern computer hardware. Unfortunately, any protocol or algorithm may have an undiscovered vulnerability that makes breaking it much easier, and hardware performance continues to improve at a good pace, bringing that ‘thousands of years’ number down significantly.

Following are some of the issues that will give an insight on how to evaluate and deploy secure embedded applications:

For an embedded system, location is as important as any other factor in determining what security measures are needed. Many embedded applications may be installed in places where an attacker has unfettered access to the hardware. When an attacker has physical access, software-based security mechanisms fail, and hardware mechanisms do not fare much better. If users are implementing world-class security in their application, then they need to make sure that the physical security employed is at least equivalent to the security in the application.

To come up with a list of potential attackers, users need to think who would benefit from compromising their systems. This might include business rivals, terrorists, secret illegal government agencies or teenagers. The people who stand to benefit the most from attacking the system are usually the most likely to attack it, but the attacker may not be interested in what users are most concerned about.

An attacker may not be after the information; it may be sufficient to shut down the application. In other cases, the attacker may just be interested in controlling the hardware. As more and more devices are networked, it is highly likely that someone will see those devices as a huge pool of hardware resources ripe for exploitation.

Wireless networks add a layer of vulnerability beyond that found in a wired network – the physical transmission medium. For a wired network, the transmission medium is a wire. Wire-tapping to eavesdrop on communications requires physical contact with the wire or close physical proximity. Wires can be routed through secure buildings, underground, on top of telephone poles, or through concrete, thus limiting the physical contact possible. With a wireless network, the transmission medium is the air. With a wireless device broadcasting information in all directions, an attacker needs only an antenna to gain access. For this reason, most wireless protocols employ some type of built-in encryption.

Some systems are secure by default, either due to higher quality software or through specific security enhancements. Users can check with others who have deployed the systems they are evaluating and try to find out what applications they have been used in before. Users can look for hardware security features that have proven records.

If users need high security for their applications, then keeping up with security news is vital. Every day, thousands of hackers and researchers are working to break security. Users should know the current state of their security technologies by learning all the known attacks, and keep up with the reports to be sure that no new attacks have been discovered.

It is easy to fall into the philosophy that one needs the best, robust, powerful security available, but one probably does not need that much. Users are concerned that the information is collected properly and delivered without being tampered with. There are less expensive methods to achieve that result without resorting to comprehensive security implementations. When evaluating security for an application, users need to think about how much security is really needed. Users can save a lot of hardware cost and development time by avoiding security they do not need.

25/02/2009 12:00 AM
Got a question about this product
More information about this product
Contact Details
Send to a friend
Dominion Electronics
Tel: 02 9906 6988
Fax: 02 9906 7145
Unit 13
Artamon
NSW 2064
Visit Website Enquire Now
Update these details
Close
Close Contact Dominion Electronics
By sending this enquiry you will also be informed of other related opportunities.
* First Name
Surname
Phone
* Your Email
State
Message

Be the first to know about new products, services and developments. Send me Ferret's newsletter.

Get new security code
* does not match
Send Enquiry

More products from Dominion Electronics

Rabbit 5000 Microprocessor From Dominion Electronics 
Rabbit 5000 Microprocessor From Dominion Electronics
Available from Dominion Electronics, Rabbit's new MiniCore series consists of compact networking modules. Available in pin compatible wired and Wi Fi versions, the MiniCore series allows for communications and networking ...
Enquire Now
News sign up

Additional Dominion Electronics News

 
With Three Industry Firsts, New Digi Core Module Speeds Development of Low Power Wireless Multimedia Devices (13/11/2009)
Digi International has today introduced the ConnectCore Wi-MX51, the industry’s first core module designed specifically for low power, wireless multimedia applications.
 
New Rabbit RCM5750 and RCM 5760 MiniCore modules from available from Dominion Electronics (13/11/2009)
Dominion Electronics have announced that the Rabbit RCM5750 and RCM5760 modules are now available, extends the current RCM5700 set with new design advantages.
PC1620 Programmable Controller – Enclosure with LCD  
PC1600 Series of Programmable Controllers - Tough, smart and very flexible (12/11/2009)
Dominion Electronics, designers and providers of hardened monitoring, automation, control and information systems are already recognised globally for their “tough and smart” products - but now there c
 
RCM5400W RabbitCore from Dominion Electronics (12/10/2009)
Digi International (NASDAQ: DGII) today announced that Heliodyne is using its Rabbit RCM5450W Wi-Fi core module for network connectivity and intelligent control of Heliodyne's industry leading thermal
 
OEM on track with tight controls on tight budgets (1/10/2009)
Using their rail hardened, embedded technology products, Australia’s OEM Technology Solutions recently provided a state-of-the-art control solution to eliminate passenger discomfort when it comes to a
RSS Feed |
News sign up |
View All 182 Additional Dominion Electronics News
News sign up

Related Articles

 
Touch terminal computers from POSMarket.com.au (24/11/2009)
Touch terminal computers from POSMarket.com.au can be found in most terminals in metros or urban cities.
 
Increased efficiency with model-based design and automatic code generation from Daanet (24/11/2009)
In many areas of industrial automation, modularity is a key factor. Reusable, self-documenting simulation models from Daanet help sustain interdepartmental know-how and considerably reduce time to market.
Automation of Pre-start checks for Forklifts and Cranes using vehicle-mounted computers 
Automation of Pre-start checks for Forklifts and Cranes using vehicle-mounted computers (24/11/2009)
Over the past few years automation has proven to be an important tool in the management of safety inspections as it enables the effective identification and management of OH&S risks.
Unipower protection and distribution panels available from Dewar Electronics 
Unipower protection and distribution panels available from Dewar Electronics (24/11/2009)
Available from Dewar Electronics, Unipower offer a suite of six protection power distribution panels.
 
Integrated security management systems from STENTOFON Communications Australia (23/11/2009)
STENTOFON Communications Australia pride themselves on their seamless integration with the applications of the top access control and alarm companies.
RSS Feed |
News sign up

Sections

  • Cd Dvd Drives
  • Circuit Board Parts
  • AC Adapter
  • Backup Batteries
  • Circuit Board Manufacturing
  • Automation Engineers
  • Circuit Board Assemblies
  • Building Automation
  • Card Plcs
  • Cable Connectors
  • Computer Accessories
  • Circuit Boards
  • Brick And Modular Plcs
  • Bus Systems
  • Alarm Systems
  • Application Specific Control Systems
  • Automation Software
  • Access Control Systems
  • Communication Equipment
  • Automation Systems
Ferret Categories
  • Automation, Process and Control
  • Computers and Software
  • Electronics and Components
  • Environment and Waste Management
  • Food and Beverage Processing
  • Health and Safety
  • Heavy Machinery and Equipment
  • Industrial Consumables
  • Industry Services
  • Materials Handling and Storage
  • Metal Working
  • Mining
  • Packaging, Labelling and Barcoding
  • Test and Measurement
  • Transport & Logistics
Ferret Newsletter

Be the first to know about new products, services and developments. Sign up for Ferret's Daily Product News.

invalid email address
enter your email address
Sign up
 

Home | Add My Business | Submit Free Article | Advertise On Ferret | eNewsletter | News Archive
About Us | Contact Us | Privacy Policy | Terms Of Use | Helpful Links

Copyright © Reed Business Information (2.4.9.002). All material on this site is subject to copyright. All rights reserved.
No part of this material may be reproduced, translated, transmitted, framed or stored in a retrieval system
for public or private use without the written permission of the publisher.