Ask Our Experts (AOE): What Is the EN303645 IoT Standard for Europe?
来源:微芯发布时间:2023-09-271714浏览
询问 AIMicrochip expert Todd Slack explains the EN303645 standard for Internet of Things (IoT) applications in the European market and how it affects embedded security silicon products.
The EN303645 is a European standardthat is being looked at by the European Union (EU) government tocreate legislation for consumer IoT products. The following question and answer comes from our Ask Our Experts | About Secure Elements playlist on YouTube.
What is the impact thatthe EN303645 standard will have for our customers?
To answer that, weshould start offin the United Kingdom (UK). The UK really pioneeredsomeefforts in the Internet of Things (IoT) space, with the IoT Security Foundationcomingupwith 13 core principles in IoT security. A number of these principles webelieve are directly associated with or rely on a secure element like our CryptoAuthentication™ family or CryptoAutomotive™ family.
Eight of these principles wouldhave a direct association there, but overall there are 13 principles andthey start with three core principles.
The first one isno defaultpasswords; that'svery bad hygiene because hackers could connect to the network and then takeover a deviceevenwith administrator rights.
The second one is to have avulnerability disclosureprocess, which Microchip has covered with our PSIRT(Product Security Incident Response Team); this is available online so thatoutside sources can log into Microchip and submit vulnerabilitiesthat they may have discovered. Then our PSIRT team would review the submission. If it is determined thatthis actually is a vulnerability, then we would go through a process to determinewhat level of vulnerability is it and how severe it is. Once we figurethat out, the team would put together some response documentation that ultimately we can make availableto our customers either on the website or directly to customers inconversation who might be impacted by it.
The third core component is to keep yoursoftware updated; that ties into things like secure firmware upgrade, which has a cleartie-in to something like a secure element where keys are associatedwith signature verification of incoming encrypted firmware payloadsbefore that firmware can be updated, but it's important that it can be updated.
Personal data is getting more attention,but from the UK's point of view in 2022, what they're trying to do is legislate, or make itrequired by law, that when building IoT devices that you have those first three coreprinciples covered with no default passwords, vulnerabilityincident response teams and software updates. In the European standard, you have the EN303645, which is prettymuch a mirror of the UK initiative. They also have 13 principles, justwith different numbers within the specification, and most of the languagein those principles is identical. It can be difficult for Original Design Manufacturers (ODMs) or tierones to really follow all these principles and understand them. One of the things that Microchip Technologyhas done to make that more simplified is we put together a blog and application note surrounding how you can categorize your risk assessment and how youcan fix that or mitigate those risks with a secure element on each of the featuresthat are listed in the specification. We can make your life easier when tryingto follow these standards in both the UK and Europe and we certainly see themexpanding around the globe as well.
If you would like to learn more, make sure to check out our Trust Platformweb page. For more information, check out our Ask Our Experts | About Secure Elements playlist on YouTube and ourSecure Elementsweb page.
Support at Every Step
We arecommitted topartneringwith you andmakingsure you have what you need to succeed.
About
Support
Quick Links
Microchip Technology Inc.
2355 West Chandler Blvd.
Chandler, Arizona, USA
新闻来源:微芯,文中所述为作者独立观点,不代表icspec立场。更多精彩资讯请下载icspec App。如对本稿件有异议,请联系微信客服specltkj。