sb-nz logo
Story image

How Gemalto aims to ensure the future of IoT

26 Sep 2018

DigiCert, Gemalto, and ISARA announced a partnership to develop advanced quantum-safe certificates and secure key management for connected devices commonly referred to as the Internet of Things (IoT).

The partnership provides significant advantages for enterprise security teams looking to secure connected devices with lengthy product lifetimes now to avoid expensive security retrofitting as quantum computing becomes more prevalent. Organisations can deploy these solutions at any scale, given that DigiCert is already capable of issuing and reliably hosting billions of digital certificates for public trust and private PKI systems. 

The work of DigiCert with ISARA and Gemalto will enable quantum-resistant certificates with the full capability of hosted, on-premise and hybrid deployment options. DigiCert already works with many companies and consortiums using PKI to authenticate, encrypt and provide integrity for their connected devices. ISARA recognises DigiCert’s track record in advancing many of the certificate innovations in use today, as well as its robust certificate management capabilities, and in operating the industry’s most ubiquitous, trusted roots. 

Gemalto offers secure key storage and management via its SafeNet Hardware Security Modules (HSMs) that integrate with DigiCert APIs to enable large-scale, automated credential issuing for connected devices via an internet-enabled gateway to distribute identity over the cloud. Certificates obtained through this partnership will be enabled with quantum-safe cryptography ahead of any breakthroughs that could eventually lead to quantum computing threatening connected device security.

Today, many IoT devices rely on RSA and ECC cryptography to protect the confidentiality, integrity and authenticity of electronic communications. However, NIST and others in the security community predict that within a decade, large-scale quantum computing will break RSA and ECC public key cryptography. DigiCert, Gemalto and ISARA recognise that crypto-agility becomes paramount for manufacturers of connected devices that will be in use a decade or more from now. 

To advance the use of reliable quantum-proof certificates, DigiCert, Gemalto and ISARA are collaborating with industry standards bodies that also are pursuing the advancement of post-quantum cryptography such as the Internet Engineering Task Force (IETF). Efforts to address quantum computing security today will support connected device manufacturers and users well into the future. 

Consider the automobile industry, which is producing more vehicles with semi- and fully-autonomous driving capabilities. A car should last for 20 years or more, and manufacturers will need to ensure that the IoT devices they install will be secure and continue to function even if there is a breakage in the RSA algorithms that would render today’s digital certificates ineffective.

Story image
AvePoint brings Salesforce Cloud Backup to channel partners
The product adds to the AvePoint suite of trusted Cloud Backup for Microsoft 365 and Dynamics 365 to provide managed service providers with backup and restore capabilities across multiple, popular SaaS providers.More
Story image
Video: 10 Minute IT Jams - Who is Okta?
Okta is an identity and access management company, specialising in secure user authentication. It's an enterprise-grade identity management service, built for the cloud, but compatible with many on-premises applications.More
Story image
Cloud services top threat vector for healthcare industry
"The coronavirus pandemic continues to highlight the unique cybersecurity needs of the healthcare industry, even as it has increased the number of threats these organisations face."More
Story image
Cybersecurity budgets still not keeping up with threats — report
Executive teams are failing to recognise the level of damage cyber-threats pose to organisations, according to Sophos — many of them taking a ‘conservative approach’ to cybersecurity expenditure.More
Story image
WatchGuard uncovers top cyber threat trends of Q4 2020
“The rise in sophisticated, evasive threat tactics last quarter and throughout 2020 showcases how vital it is to implement layered, end-to-end security protections."More
Story image
Almost a third of malware threats previously unknown - HP report
A new report has found 29% of malware captured was previously unknown due to the widespread use of packers and obfuscation techniques by attackers seeking to evade detection. More