Perimeter
6/17/2013
12:04 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

DeepCover Secure Authenticator From Maxim Integrated Protects Designs With Strong Public-Key Cryptography

Integrated authenticator simplifies interconnect complexity in medical sensors and industrial applications

SAN JOSE, Calif., June 17, 2013 /PRNewswire/ -- Maxim Integrated Products, Inc.

(NASDAQ: MXIM) today announced that it is now sampling the DS28E35 DeepCover® Secure Authenticator, a highly secure cryptographic solution for a host controller to authenticate peripherals. The DS28E35 integrates a FIPS 186-based, Elliptic Curve Digital Signature Algorithm (ECDSA) engine to implement asymmetric (public-key) cryptography to operate a challenge-and-response authentication protocol between a host controller and attached peripherals, sensors, or modules. Operating over a single pin on the 1-Wire® interface, the

DS28E35 reduces interconnect complexity, simplifies designs, and reduces cost.

It provides crypto-strong authentication security for many applications, including medical sensors, industrial programmable logic controller (PLC) modules, and consumer devices.

(Logo: http://photos.prnewswire.com/prnh/20120912/SF71654LOGO)

The use of ECDSA public-key cryptography saves cost and reduces key management complexity by eliminating the need for the host controller to store and protect the authentication key, which is required for comparable symmetric (secret-key) solutions. The DS28E35 operates with a key pair: a public key that resides with the host and an associated private key stored in the DS28E35. As a primary benefit of ECDSA, there is no security requirement to protect the host public key. It is imperative, however, to protect the private key stored in the DS28E35. This is accomplished through Maxim's DeepCover security technologies, which provide the strongest affordable protection against die-level attacks that attempt to discover the private key. DeepCover technologies include advanced die routing and layout techniques, additional proprietary methods for private key protection, and circuits that actively monitor for tampering.

Key Advantages

-- ECDSA asymmetric, public-key cryptography saves cost: eliminates the

need for additional secure authentication key storage ICs in the host

system.

-- High integration reduces costs, simplifies designs: ECDSA engine with a

1-Wire interface; nonvolatile (NV) memory; hardware random number

generator for signatures and key-pair generation; decrement-only usage

counter; and DeepCover invasive-attack protection circuitry.

-- Reduces interconnect complexity: 1-Wire interface allows operation from

a single dedicated contact which, in turn, improves reliability and

performance.

-- Easily adapts to a host-peripheral system where secure authentication is

required.

Industry Commentary

-- "Customers are increasingly looking for the advantages offered by

asymmetric public-key crypto for their secure authentication needs,"

said Scott Jones, Executive Director at Maxim Integrated. "We've

combined our extensive embedded security expertise with the integration

of key features to provide a solution that is both cryptographically and

physically secure and easy to add to an end application."

-- "The weakest point of a symmetric-key based host-peripheral secure

authentication system is typically the host component where secret keys

are often not protected sufficiently," said Christopher Tarnovsky, Vice

President of Semiconductor Security Services at IOActive. "The use of a

public-key authentication solution eliminates this security risk."

Availability and Pricing

-- Available in a 6-pin TSOC package and a 2mm x 3mm 8-pin TDFN-EP package.

-- Specified over the -40°C to +85°C temperature range.

-- Pricing starts at $1.08 (1000-up, FOB USA).

Download a hi-res image of the DS28E35 secure authenticator.

1-Wire and DeepCover are registered trademarks of Maxim Integrated Products, Inc.

About Maxim Integrated

At Maxim Integrated, we put analog together in a way that sets our customers apart. In Fiscal 2012, we reported revenues of $2.4 billion.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.