Select your language

How to confront the evolved hacker

Hacker evolucionadoThe fundamental importance of the secure execution environment in access control.

by Luis Carlos Delcampo*

The cost of cybercrime is on the rise
An unfortunate consequence of a well-connected world (i.e., the proliferation of the Internet of Things) is that the cost of cybercrime has risen dramatically. A recent report has put these data into figures: Globally, cybercrime costs about $600 billion per year, up from $500 billion in 20141.

Poorly protected Internet of Things (IoT) devices can be a problem, offering new and simple ways for hackers to steal information or access valuable data, networks, or physical assets (source 4). In fact, recent data suggests that the cost of poorly protected device identities is between $15 billion and $21 billion or 9% to 13% of total economic losses in the United States caused by cyber events (estimated to represent a total of $163 billion2).

- Publicidad -

Together, all these large numbers converge into one reality: it has never been more necessary than now to have a reliable identification for connected devices. This is where the Secure Execution Environment (TEE) comes in.

What is a Secure Execution Environment (TEE)?
How to secure devices using the principle of isolation

A secure execution environment (TEE) is an isolated and secure zone of a central processor that provides guaranteed integrity of application execution, along with the confidentiality of assets such as credentials, certificates, keys, and data. It offers high levels of confidence in the asset management of the surrounding environment, as these assets are protected at rest from "unknown" attackers external to the device's TEE.

Specifically, the "secure" part of the TEE requires that all assets, codes, and other TEE-related device boot chain components (e.g., bootloader, operating system platform, installed application images) have been installed and initiated using a methodology that requires the initial state to be as expected:

• Firmware is verified at startup. Linux files and device firmware are loaded, and a secure memory partition is created for the secure execution environment.
• Validates that the content has not been modified while it was stored at rest.
• Credentials (e.g., keys and certificates), including application programs, and everything in the untrusted domain are protected.
• Content is encrypted on disk and decrypted while transferring from one section of memory to another, freeing up the processor.

After verifying integrity, the bootloader enables access to encrypted file systems and transfers execution to the next stage of the boot process.

Hackers hate teE. The TEE employs a higher-level security booster.

- Publicidad -

Isolation is the key to obtaining a hardened device in terms of security, while hardening is the process of securing a system by reducing the vulnerability surface. Typically, reducing available attack channels involves modifying default passwords, removing unnecessary software, usernames, or logins, and disabling or removing unnecessary services. The combination of the concept of isolation and that of strengthening security is the essence of TEE, and it becomes the enemy of our enemies (hackers).

Increased security
Hackers are notoriously intelligent. They make a living by creating methods to decrypt encryptions. TEE goes beyond encryption: it creates blocked "trusted zones," dividing processor package resources and peripherals into trusted domains. Simply put, credentials, certificates, keys, etc., are stored so that they are inaccessible to hackers, even when the power supply is interrupted.
There's no doubt that TEE makes devices more secure, but it can also improve performance and functionality.

Better performance and functionality
TeE is the ultimate in multitasking: it encrypts content while it is stored in non-volatile memory and decrypts it while transferring it to another section of memory. This frees up the processor and enables performance at a higher level. And because the TEE is a software solution (firmware), its functionality can be easily customized and updated.

Basically, the TEE is a super performance enabler. Just what you need for your access control solution.

TeE instrumentation in physical access control solutions should be expected: Access control devices live in the IoT universe.

If you've read this far, you probably have some level of responsibility for your company's physical access control system.

- Publicidad -

Regardless of how many buildings or devices you have installed in your application, they are generally connected to each other, to external devices and to host client computing devices using an IP or IoT network infrastructure (making them potential targets for cyberattacks).

We all remember how easy it has historically been for hackers to access devices via the serial port, etc. With the TEE, any attempt to modify the system would make it "impossible to start."

TEE-protected access control devices offer a higher level of confidence in the validity, isolation, and protection of assets stored in this space. In turn, this leads us to claim that operating systems (OS) and applications running within that space are more reliable.

iSTAR Edge G2: First cyber-hardened IP perimeter access control device to use TEE

iSTAR Edge G2 by Tyco | Software House is the first perimeter access control device that uses a TEE to ensure the confidentiality and integrity of code and data. This allows you to reliably store keys and other cryptographic elements, as well as manage a secure startup process to ensure authenticated sources of hardware and software.

• Safe manufacturing from the start: customized and protected with a proper and well-established chain of trust.
• Secure Boot: The entire startup sequence is authenticated.
• Secure updates: The driver will be updated only with software that is considered reliable.
iSTAR is already recognized as one of the most securely reinforcing IP edge portfolios on the market, and the introduction of iSTAR Edge G2 and its TEE implementation reaffirms its advanced cybersecurity protection.

Advanced cyber protection
Hackers are here to stay. It is a sad reality that has partially shaped the industry and professions in which many of us work. These "bad actors" evolve rapidly, and so must the technology used to block their actions.

The secure execution environment (TEE) is one of these technologies. It enables modern devices to offer a wide range of functionality while meeting the requirements of software developers, service providers, and security professionals who care about privacy, confirmation, authentication, validation, feasibility, and all aspects of security.

References
1. The cost of cybercrime. Internet Society. Published on February 23, 2018. Retrieved 14 December 2020. https://www.internetsociety.org/blog/2018/02/the-cost-of-cybercrime/
2. Mismanagement of Device Identities Could Cost Businesses Billions: Report. Published on February 24, 2020. Retrieved 14 December 2020. https://rootdaemon.com/2020/02/24/mismanagement-of-device-identities-could-cost-businesses-billions-report
3. Trusted execution environments: What, how and why? TechTarget IoT Agenda. Published on April 18, 2018. Retrieved 19 December 2020. https://internetofthingsagenda.techtarget.com/blog/IoT-Agenda/Trusted-execution-environments-What-how-and-why

* Luis Carlos Delcampo is Product and Marketing Manager of the Access Control line of Tyco Security Products for Latin America.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

One comment

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The Challenge of Global Instability: Towards a Comprehensive Security and Defense Response

The growing convergence between physical and digital threats is forcing organizations to rethink their security strategies. Faced with this scenario, there is a need for comprehensive approaches...

AI applied to medical security

AI applied to medical security

The Directorate of the Medical Emergency System (SEM), attached to the Ministry of Health of El Salvador, strengthened its technological infrastructure with the modernization of its video...

Eight Red Dot Awards Highlight Innovation in Technology Design

Eight Red Dot Awards Highlight Innovation in Technology Design

International. The technology company Ajax Systems announced that it has won eight awards in the Red Dot Design Award, one of the most prestigious global awards in the field of industrial design....

Villa María del Triunfo reinforces its security with intelligent video surveillance

Villa María del Triunfo reinforces its security with intelligent video surveillance

Peru. The district of Villa María del Triunfo has launched an intelligent video surveillance system that already shows results in terms of citizen security and that will be expanded in a second...

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Milestone Systems grows 10% by 2025 and reinforces its commitment to artificial intelligence and intelligent video

Denmark. The company reported net income of $340 million in 2025, representing a 10% growth from the previous year. The company spent about a third of this revenue on innovation, with an emphasis on...

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

Micro Key Solutions Reinforces Latin America Strategy with New Key Appointments

United States. In response to the growth in demand for monitoring and management software solutions in the security industry, Micro Key Solutions announced the expansion of its operations in Latin...

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Grupo Multisistemas strengthens its presence in Mexico with a new office in Morelia

Mexico. Grupo Multisistemas de Seguridad Industrial (GMSI) advances in its national growth strategy with the inauguration of new offices in Morelia, Michoacán, with the aim of expanding its coverage...

Case study: Security system modernization with artificial intelligence and centralized monitoring

Case study: Security system modernization with artificial intelligence and centralized monitoring

Mexico City. The Superior Audit Office of the Federation (ASF) implemented an ambitious technological renovation project in its five headquarters located in Mexico City, with the aim of...

Automated key and equipment management strengthens security in mining operations

Automated key and equipment management strengthens security in mining operations

International. Access and equipment management in the mining industry is evolving towards increasingly automated models, in response to operational complexity and occupational safety demands.

Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter