Energy-efficient encryption for the internet of things
news.mit.edu
news.mit.edu
Most problems in IoT security can be reduced to "nobody cares". If vendors can't be bothered to stop using default passwords, how are you gonna convince them that they add an extra chip to have more performant crypto? (Which almost certainly they'll use wrong anyway.)
The one I'm intimately familiar with is in smart-metering with gas-meters. These things a battery powered and need to last for ~20 years on that battery. Simultaneously, they're dealing with financial data and communication, therefore all communications are encrypted & authenticated.
This device, although may be expensive tho... when you're dealing with 10's of millions of units, that cost really counts.
Hopefully someone (ARM) will snap start embedding this type of device within the Cortex-M range... (yes, I know, there already is crypto-acceleration, but more is better).
I guess research chips like those end up serving as inspiration for the CPU designers of Intel/AMD/ARM etc. to evaluate which encryption instruction sets might be good to include in the future? Or are the fast vectorized multiplication operations and such already good enough to implement fast asymmetric crypto and no specialized instructions similar to AES-NI are needed? (Though of course this paper seems to imply that specialized hardware is useful)
Energy-efficient protocols and hardware architectures for transport layer security — https://dspace.mit.edu/handle/1721.1/111861
eeDTLS: Energy-Efficient Datagram Transport Layer Security for the Internet of Things — http://ieeexplore.ieee.org/abstract/document/8255053/
There are probably others. I look forward to seeing this paper when it's published though.
But no, this is apparently a generic ECC acceleration unit. It's still a bignum system but a somewhat more focused one. I would love to see some comparative benchmarks - not only on speed, but also on driver implementation complexity.
I don't think the limit is secret.
Hardware will always be king. It's the platform. Platforms should assume more responsibility, so that applications can assume less. It stands to reason that more applications would exist as we make it easier to build them.
Furthermore, less people can fuck up implementations if they are embedded in physical metals and rocks. Take more power away from the human, because the human cannot be trusted.
The advantage of ECC is that it's stronger for a given number of bits. Now if we have hardware acceleration, is that still valid?
BTC ASIC chips are relatively simple sha-256 generators, whereas the chip from these MIT researchers is somewhat more complicated and can handle elliptic-curve public-key cryptography.
I'm curious if the price/power tradeoff here is worth it. They're making a bigger, more expensive chip that uses less power, but current solutions already use quite little.
I'm disappointed in the 1/400 power, 1/10 memory, 500x faster nonsense though...some actual specs would've been nice.