Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Wednesday, October 19, 2016

Crossroads - INNOTRANS 2016


Terry Staycer
Global Business Development Manager 
BlackBerry






Readers of this blog might be interested in hearing how demands for software safety and security are growing not only in automotive, but in other transportation areas as well – specifically, the railway industry.
 

Last month in Berlin, the 11th annual largest global railway industry event took place.  It was a smashing four-day success in terms of attendance and powerful discussions.   I was honored to attend this event. Overall, the hot topics revolved around improving mobility issues, digitization in rail passenger and freight transport, and technology for digital services.  Safety and security  remain key points of concern.   

QNX's hardware partner, MEN Micro, introduced Internet on trains to ease passenger communication and increase convenience.  However, that comes with increasing risk in terms of bad actors' being able to hack into a rail network.  It is critical to ensure that rail systems are at their most secure and that there is no potential violation to a train.
 
Here is a summary of some other key takeaways from what is the leading trade fair for transport technology:

Evident Re-Focusing
There is a re-focusing of development regarding interlocking and signal control among many of the big rail players such as Alstom, Bombardier, GE, and many others.  Application code, hardware, electronics, and sensors are being outsourced. The rail industry is maturing like the automotive market.

SIL 2. All the way
Customers are pursuing requirements from European and Chinese regulatory commissions, and increasingly those requirements are emerging as SIL-2, and not the anticipated SIL-4.  With these lower Safety Integrity Levels (SILs), the level of system failure increases. Of course customers are still asking for SIL-4, but this is an interesting trend to note.

Security is Critical
Security is a maturing requirement.  At the recent Deutsche Bahn Cyber Security Congress security was a top priority, and it was a hot topic at Innotrans as well. Some of the questions emerging about the security include: If there is a cybersecurity violation, how long does it take to recover? And, how does one architect a system for resiliency to cyberattacks?

Fail Safe vs. availability

Fail safe is good, but high availability is a demand. This topic dovetails into the statement above. Systems must be available in a sense that requires redundancy and fail safe. QNX is well positioned to address this trend with a microkernel based operating system architecture that delivers high-availability and reliability, making it perfect for mission-critical operations such as rail safety. 

China and North America Expansion
China was the most represented company outside of Germany.  The Chinese high speed rail network will span 25,631 KM by 2030. China will boast a total track length of 120,000 KM by 2020.  In addition, North America will invest over $9.8 Billion per year  towards modernization continuing until 2022. Signaling, locomotives, and rail cars have the highest priority.

It is exciting to watch these trends develop and see which new ones will emerge.   

Already looking forward to Innotrans 2017!

 


Thursday, August 18, 2016

Security Matters for the Software-Defined Car


Bill Boldt
Business Development Manger, Security, BlackBerry
wboldt@blackberry.com

  
Certicom, the crypto expert in the BlackBerry Technology Solutions family is positioned to lead the way to a secure software-defined future for the automotive industry –because when it comes to the security, real-world experience matters.
 

Certicom is a recognized leader in public key infrastructure (PKI) security design,innovation, and delivery. PKI is a foundational technology that has become the cornerstone of real world security across the internet, mobile, medical, financial, government,military, consumer, automotive, industrial, IoT, and just about every application that communicates information electronically. 

Public Key Cryptography uses public-private cryptographic key pairs to sign digital certificates and provide the essential elements of security, which are confidentiality, data integrity, authentication, and non-repudiation. PKI establishes the infrastructure that defines how digital certificates are created, distributed, stored, and revoked.



Public Key Cryptography Matters

It is not at all an overstatement to characterize Public Key Cryptography as having established the main way that security is provided throughout today’s (and tomorrow’s) connected world. In fact, anyone who has ever logged on to a secure web site such as e-commerce or e-banking has used Public Key crypto, most likely without even knowing it. it is already built into personal computers and smart phones, and it won’t be long before it is built into every embedded application as well. And, that is a very important notion to grasp.



Proven PKI solutions from world leading software and security infrastructure suppliers like Certicom increase device (e.g. semiconductor chip and board) security, fight counterfeiting and cloning of products and firmware, promote product and personal identity authentication, secure asset management in supply chains, and improve the security of numerous other applications, including the emerging Internet of things (“IoT”).

    
Public Key crypto's tremendous growth is being increasingly driven by two powerful forces: 1) the widespread adoption of autonomous communicating devices, and 2) the realization that such devices absolutely must be authenticated.

Supply Chain Security Matters
The long pole in the tent for  security in the software-defined car is in fact securing the supply chain. 

Security assets (such as crypto keys, unique serial numbers, etc.) must be installed into the devices at manufacturing time.  Devices must be distributed to and installed into vehicles in globally located factories. Devices must be warehoused worldwide for subsequent repairs.  Secure devices must be updateable at the dealers and repair shops.  Aftermarket suppliers must be able to sell and update secure devices. These requirements present a logistical tangle. Making a device such as an ECU or secure processor secure means that it will be unique. 


However, by definition that device cannot be used anywhere else.  It becomes a unique stock keeping unit (SKU), which is averse to the purpose of flexible, just in time manufacturing flows.  Security versus flexibility is a serious trade off that must be managed carefully. To maintain the maximum amount of flexibility, personalization and updating should be moved as close as possible to the very last minute.   That means it must happen not only in the factory, but in the field and via updates.  Each car maker faces the same issues, and will have to design and manage a secure device manufacturing system, security certificate management system, and a secure updating system – all of which must be global and long term in nature.
  

These are the type of things that Blackberry can provide  based upon decades of experience in securing mobile infrastructure and devices, to a level that no other company has done.



Experience Matters

Security is as elemental to an electronic system as DNA is to an organism—and security is BlackBerry’s DNA.


For the connected autonomous car of the future-- security has to be inside and outside the car, in the supply chain,  and updateable.  BlackBerry has the state of the art experience to to those things due to proven experience in making products secure, in high volumes, and in the supply chain.