Technology Review - Published By MIT
Advertisement

The Encrypted Chip

What will IBM's new hardware-based security technology be used for?

By Kate Greene

Wednesday, April 19, 2006

smaller text tool iconmedium text tool iconlarger text tool icon

IBM recently announced an effort to enmesh data security in the chips found in cell phones, PDAs, and other portable devices. More than half of all unprotected data can be found on these gadgets, says the company, and encryption that relies on software is not as secure as encryption built into hardware.

Some experts believe that IBM's new technology could be useful in certain instances, such as when a PDA containing sensitive, proprietary information goes missing. But the technology also raises the hackles of those who fear it might one day be used by companies -- in the entertainment industry, in particular -- to further restrict people's uses of copyrighted material. Content providers, the argument goes, could use such a chip to lock movies, music, or television shows to a gadget or computer, keeping them from being distributed.

This new IBM technology, called SecureBlue, is meant to address some of the limitations of software security, especially in portable electronics, says Guerney Hunt, senior manager for distributed infrastructures, IBM Research. "This kind of encryption technique was developed because it's increasingly possible for these devices to fall into the wrong hands," he says. "Software cryptography has to be turned on and turned off, and it can be defeated by software attacks." But if the security and tamper protection is incorporated into the chip, he says, sensitive information cannot be removed without destroying the chip.

SecureBlue is a set of chip circuitry that uses a common type of encryption called Advanced Encryption Standard. When data enters a chip with SecureBlue technology, it encounters an extra processing step that encrypts the data as it travels throughout the chip and onto other device components such as the hard drive. Hardware encryption does not replace security software, but rather helps to protect data that might otherwise slip past the radar of security software.

For instance, when programs run, they copy small amounts of information to a hard drive, where it may be unintentionally stored, explains Burt Kaliski, vice president of research at RSA Security, a Bedford, MA-based digital security company. As this happens, encryption software might not account for all the data that is stored on the hard drive of a device. This is "one of the vulnerabilities of a computer system," says Kaliski. But if the data is encrypted from the start, he says, that vulnerability is addressed and all of the data is securely in the hardware of the device. Kaliski adds that going after unencrypted remnants of data stored on hard drives is a "very sophisticated attack" that would be difficult to carry out.

But some industry observers aren't so impressed. David Wagner, professor of computer science at the University of California, Berkeley, says that encrypting the chip doesn't address the majority of cybercrime. "Encryption isn't the main problem we face today in the security field," he says; instead, most threats come from viruses, worms, and online identity theft. "There are certainly some applications that can benefit from hardware acceleration of cryptography," says Wagner, but most computer users "don't need this fancy stuff. Existing technology is adequate for many purposes."

Comments

  • Security chain on devices
    Security for security sake is fine. And I think chip based encryption works well in this environment. If however, you want DRM this may be trickier as at some point the device needs to output to a human. This is essentially a decryption at which point it could be copied. Unless Hollywood are willing to implant decryption chips in our brains there will always be a point at which copyright can be copywronged.
    Rate this comment: 12345
    Guest (Brett)
    04/19/2006
    Posts:1
    • Virus differentiation
      I often have to turn off my anti-virus software to get certain programs to work correctly.  What happens when I can't turn it off?  "Oops... sorry.  We blocked the proper operation of a piece of software who's originators lacked the funding to develop with our chip."  How will this affect the open source community?
      Rate this comment: 12345
      Guest (Jonathan)
      04/19/2006
      Posts:1
  • Distribution Control App OK
    If my devices are associated to each other by their security chip, and the license for software usage is defined, then there is nothing wrong with using this chip to control content distribution.  Some limits on the results of detecting inappropriate distribution are needed.  You can notify me that this copy is illegal and stop the file, but you can't report it or disable my system in any way by allocating any resource beyond the notification to user and file script interrupt.
    Rate this comment: 12345
    Guest (Roger)
    04/20/2006
    Posts:1
  • For secure data today, use BlackDog Linux
    There are slao inexpensive, secure data, fit-in-your-pocket devices like BlackDog which use thumbprint authentication already.
    Rate this comment: 12345
    Guest (Richard Karpinskl)
    04/30/2006
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Malleable Maps, Artistic Robots and Bubble Interfaces
Technology Review January/February 2010

Current Issue

Security in the Ether
Information technology's next grand challenge will be to secure the cloud--and prove we can trust it.
Advertisement
Advertisement
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2010 Technology Review. All Rights Reserved.