WIBU-SYSTEMS

Perfection in Protection, Licensing, and Security

{{ moduleLabel }}
{{ label }}

The Blurry Box Encryption Revolution

MarketingWIBU-SYSTEMS AG el 2 de marzo de 2017 9:04 horas

“The system should not require secrecy and it must not be a problem if it falls into enemy hands.”

Those were the words of Auguste Kerckhoffs, who published two articles in 1883 in which he surveyed the military ciphers of the time and proposed six principles for the design of new ciphers. One of those principles, known as Kerckhoffs’ Principle, remains a fundamental foundation of modern cryptography.

Encryption has become a vital consideration in an increasingly connected world. Conventional software encryption schemes often rely on the principle of “security through obscurity”. According to this principle, the security of a system is fundamentally tied to the secrecy of the protection mechanisms that are shielding it from attacks. As a result, all programs protected by the same protection scheme can be hacked using the same attack method. Put differently: it can be worthwhile for a hacker to invest considerable effort into a generic attack on a given protection method, since the attack is "scalable" and commercially exploitable, and will soon finds its way into a new wave of hacking guidelines for the entire hacking community.

However, if the protection was designed in such a way that an extensive hacking effort is required for each new protected program, the overall risk would be decreased. In this case, the attack might be successful for a single program only, which would significantly compromise the commercial viability and scalability of the hacking operation. In order to achieve this goal, the protection design requires a different approach. Rather than keeping the method secret, Kerckhoffs’ Principle predicates that only the encryption key requires utmost secrecy. That’s the basic concept behind this new technology called Blurry Box.

The application of Blurry Box in today’s smart factories can provide dramatic benefits, particularly in protecting sensitive data. Sensitive data can include production data in many forms and sizes, such as 3D blueprints or punch schemes for embroidery machines, or the technology data or configurations used in manufacturing processes. This invaluable data needs to be safeguarded against know-how theft, counterfeiting, and tampering, otherwise software-as-a-service will easily degrade into piracy-as-a-service. Applying Kerckhoffs’ Principle would provide encryption methods associated with hardware anchors of trust and ensure IP confidentiality and the integrity and authenticity of digital signatures.

The 3rd edition of the Industrial Internet Consortium’s (IIC) Journal of Innovation includes an in-depth description of Blurry Box encryption which was developed in conjunction with Wibu-Systems and the FZI Research Center for IT at the Karlsruhe Institute of Technology. The article, Blurry Box Encryption Scheme and Why it Matters to IIoT, illustrates the security benefits in use cases in several areas, including Industrie 4.0, IoT, automation, automotive, banking, medical, microgrid controls, and the textile industries.

With software at the foundation of new Internet-connected devices, modern encryption mechanisms are critical to protect IP from copying and reverse engineering. And, these mechanisms are just as vital in the Industrial Internet of Things, where connected devices, machines and factories need strong safeguards against malicious tampering that can pose serious threats to public safety and critical infrastructure.

Security issues in Smart Factories is discussed further in the IIC’s technical white paper, Smart Factory Applications in Discrete Manufacturing, published by the IIC Smart Factory Task Group.

Inicie sesión o regístrese ahora y disfrute de todas las ventajas de una comunidad.

Para obtener toda la funcionalidad del Foro de IndustryArena es necesario iniciar sesión o registrarse. Este proceso es absolutamente gratuito.

Password forgotten?
Solicitud de contacto
Guest Photo
Your message
The controller within the meaning of Art. 4(7) GDPR is: IndustryArena GmbH, Schneiderstr. 6, 40764 Langenfeld, Germany.
You may reach our data protection officer under dataprotection@industryarena.com.

Purpose of processing
We process your personal data concerning the use of the contact form and the communication with the company of the newsroom as well as the transmission of your data to this company in accordance to Art. 6 (1a) GDPR. This constitutes a legitimate interest for us in accordance to Art. 6 (1f) GDPR.

Recipient of the data
Within our organization, those units gain access to your data, which are necessary to fulfil the above purposes.
Personal data will only be transmitted to third parties if this is necessary for the aforementioned purposes or if another legal basis exists. If necessary, we conclude the corresponding data protection agreements with third parties, in particular pursuant to Art. 28 GDPR.

Data storing
Your data will be transmitted to the company of the newsroom for further processing. The period of storing is the duration of the processing of your request by the respective company.

Seleccionar persona de contacto

Newsroom Logo

Opciones de diseño

  • Título Color de fuente:
  • Contenido Color de fondo:
  • Contenido Color de fuente:
  • Navegación Fondo:
  • Ficha Color de fuente:
  • Pestaña activa Color de fuente:
  • Enlace Color de fuente:
  • Enlace activo Color de fuente:
  • Imagen de fondo Color de fondo

    ¿Cómo quieres colocar la imagen de fondo?

    Tenga en cuenta: Los banners y los rascacielos sólo se guardan para el idioma actual. Para otros idiomas, cambia el idioma con el botón de la parte superior derecha.

    Establecer el enlace para la imagen de fondo

  • Gráfico de cabecera

    ¿Cómo desea alinear el banner?

    Tenga en cuenta: Los banners y los rascacielos sólo se guardan para el idioma actual. Para otros idiomas, cambia el idioma con el botón de la parte superior derecha.

    Introduzca el destino del enlace para el banner

  • Skyscraper

    Introduzca el destino del enlace para el Skyscraper

Tenga en cuenta:

Los banners y los rascacielos sólo se guardan para el idioma actual. Para otros idiomas, cambia el idioma con el botón de la parte superior derecha.