{"id":78809,"date":"2024-09-06T04:27:33","date_gmt":"2024-09-06T04:27:33","guid":{"rendered":"https:\/\/electronicsmaker.com\/?p=78809"},"modified":"2024-09-06T04:27:36","modified_gmt":"2024-09-06T04:27:36","slug":"commscope-pki-center-an-ally-on-the-path-to-the-iot-device-security-certification-and-production-for-matter-products","status":"publish","type":"post","link":"https:\/\/electronicsmaker.com\/commscope-pki-center-an-ally-on-the-path-to-the-iot-device-security-certification-and-production-for-matter-products","title":{"rendered":"CommScope PKI Center&#x2122;: An ally on the path to the IoT Device Security certification and production for Matter products"},"content":{"rendered":"<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><img fetchpriority=\"high\" decoding=\"async\" width=\"600\" height=\"257\" src=\"https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/Featured-image-1140x489-20.jpg\" alt=\"\" class=\"wp-image-78811\" srcset=\"https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/Featured-image-1140x489-20.jpg 600w, https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/Featured-image-1140x489-20-300x129.jpg 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/figure><\/div>\n\n\n<p>One of Matter development\u2019s biggest issues is a potentially false sense of security resulting from improperly implementing specifications. According to CommScope, a member of the ST Partner Program, failing to manage certificates or device attestation credentials (DACs) correctly can lead to security vulnerabilities, as DACs are the most sensitive parameters for establishing device authentication and trust within the Matter ecosystem. It can also mean a company can fail to meet the IoT Device Security Specification from the CSA, the consortium behind Matter.<\/p>\n\n\n\n<p>Launched in March 2024, the specification establishes unique Critical Security Parameters (CSPs) and follows best practices on secure storage and management processes. Once device manufacturers meet the certification criteria, they obtain Product Security Verified Marks. Hence, the IoT Device Security Specification represents a significant milestone toward what some are calling a \u201cglobal cybersecurity standard for smart home devices\u201d1, by ensuring a more secure ecosystem that\u2019s capable of meeting today\u2019s growing threats. CommScope and ST are, therefore, collaborating to ensure STM32 developers can rapidly meet these requirements.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Security no longer optional<\/h4>\n\n\n\n<p>The entire industry has high hopes for Matter, which explains why so many are adopting it, from Apple to Samsung, Amazon, and Google, among many others, and why ST is a promoter member of the CSA. We even released an X-CUBE-MATTER software package to help developers rapidly release their products to market thanks to pre-certified code and demo applications. Moreover, we have already shown demos of a certified Matter system running on STM32 MCUs. The CSA explains that it created Matter \u201cwith security and privacy as key design tenets.2\u201d Consequently, as a promoter member, ST ensured our customers have all the tools and hardware needed to meet the latest security requirements.<\/p>\n\n\n\n<p><strong>Sleeping on the job<\/strong><\/p>\n\n\n\n<p>The reason behind this new security push is simple. Until 2010, many developers didn\u2019t even think the vast majority of IoT devices warranted security safeguards. This led to severe issues like the Mirai Botnet, which exploited IoT devices to launch massive DDoS attacks. Similarly, when researchers showed how they could remotely take control of a car by exploiting inherent vulnerabilities3 or that hackers spied on children\u2019s bedrooms by breaching popular home security cameras4, people started to take notice. The CSA\u2019s emphasis on security and privacy recognizes the critical importance of safeguarding users and devices in a world where threats are increasingly complex.<\/p>\n\n\n\n<p><strong>Rude awakening<\/strong><\/p>\n\n\n\n<p>The problem is that few device manufacturers have the expertise to properly design and implement security measures. What\u2019s even worse is that many developers vastly underestimate what it takes to implement security in a Matter system. For instance, the IoT Device Security Specification requires that the private key never leave its origin device. As a result, many companies only discover their non-compliance when they enter the certification program to obtain the Product Security Verified Mark. This often leads to significant delays and expenses when teams must revisit their initial designs and implementations and address the security issues preventing them from obtaining the IoT Device Security certification.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Intentionally secure<\/h4>\n\n\n\n<p><strong>STM32 and security<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignleft size-full\"><img decoding=\"async\" width=\"400\" height=\"264\" src=\"https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/ST32509_smart-home_EP3-01.jpg\" alt=\"\" class=\"wp-image-78812\" srcset=\"https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/ST32509_smart-home_EP3-01.jpg 400w, https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/ST32509_smart-home_EP3-01-300x198.jpg 300w\" sizes=\"(max-width: 400px) 100vw, 400px\" \/><figcaption class=\"wp-element-caption\"><em>Matter devices will end up everywhere. That\u2019s why the ST and CommScope partnership is so important.<\/em><\/figcaption><\/figure><\/div>\n\n\n<p>Any security implementation starts at the hardware level. No amount of software can save a device that doesn\u2019t offer strict physical and logical safeguards. Hence, the STM32WB55, which many use to run their Matter application, offers tamper protection mechanisms. It also has multiple crypto cores accelerating AES symmetric and RSA\/ECC asymmetric cryptography. Moreover, it supports secure firmware installations and provides key storage and management services. Furthermore, the STM32WBA5x devices, like the newly launched STM32WBA54 and STM32WBA55, which can work as a radio co-processor in a Thread border router in a Matter ecosystem, can target a SESIP3 and PSA Certified Level 3 certification. Accordingly, developers know that these devices can help them meet modern specifications.<\/p>\n\n\n\n<p><strong>CommScope security solutions<\/strong><\/p>\n\n\n\n<p>To allow developers to gain firsthand experience with Matter Device Attestation Credential provisioning without requiring software development, CommScope provides a video showcasing the process with a test DAC on an STM32WB5MMG evaluation board, the STM32WB5MM-DK. The CommScope solution provides services that handle certificate authority, provisioning services, certificate lifecycle management services, boot loaders, and app code signing. The services predate Matter and work in a wide range of IoT applications. In fact, their expertise has helped them anticipate the needs of developers, which is why ST featured CommScope Security Solution during Embedded World 2024.<\/p>\n\n\n\n<p>In the video, CommScope shows a demonstration software package, which includes:<\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-streamable wp-block-embed-streamable\"><div class=\"wp-block-embed__wrapper\">\n<iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" title=\"pki-provisioning\" src=\"https:\/\/streamable.com\/o\/ogvuvg#?secret=edXwFMAhVz\" data-secret=\"edXwFMAhVz\" frameborder=\"0\" scrolling=\"no\" width=\"1920\" height=\"1080\"><\/iframe>\n<\/div><\/figure>\n\n\n\n<ol>\n<li>The DAC provisioning firmware<\/li>\n\n\n\n<li>The programming station application<\/li>\n<\/ol>\n\n\n\n<p>The DAC provisioning firmware runs on the STM32WB5MMG to generate the DAC key pair and its corresponding Certificate Signing Request (CSR) within the device. As a result, it keeps the private key secure. Users can use STM32CubeProgrammer, our popular debugging and flashing tool, to flash the DAC provisioning firmware onto the evaluation board. As for the programming station application, it facilitates communication between the STM32WB5MMG and the CommScope\u2019s Matter DAC provisioning server (PKIWorks Essentials) by forwarding Certificate Signing Requests (CSRs) and receiving DACs. The demo is also close to a real-world example. When it\u2019s time to move to production, the manufacturer must simply transition to a software package enabling the provisioning of DACs tailored for the product in question.<\/p>\n\n\n\n<p><strong>Simplified Path to Production &amp; Certification<\/strong><\/p>\n\n\n\n<p>ST and CommScope recognize the pain points that come from transitioning from a proof-of-concept with a demo package to a production line. Hence, CommScope offers a pre-integrated and tested pre-production solution with an integration guide for our STM32WB5MM-DK Discovery Kit. Device manufacturers can thus create a factory-deployable workflow ready to roll out and fit into their existing factory processes with minimum software customization. Both ST and CommScope understand the challenges involved in modifying manufacturing processes. It involves careful planning and adjustments to optimize production yields, especially when integrating DAC provisioning into manufacturing lines.<\/p>\n\n\n\n<p>Consequently, to facilitate the transition from test DACs to production DACs, device manufacturers only need to provide their company name, vendor ID, and\/or product ID to CommScope. The company will then create a specific Product Attestation Intermediate (PAI) essential for DACs issuance during production. Each device manufacturer\u2019s specific PAI(s) is linked to CommScope\u2019s CSA-approved non-VID-scoped Product Attestation Authorities (PAAs) and recorded in the CSA\u2019s blockchain, known as the Device Compliance Ledger (DCL).<\/p>\n\n\n\n<p>Therefore, ST and CommScope\u2019s pre-integrated software package includes necessary baseline software implementation and offers direct Certificate Authority Services tailored for various device manufacturers. In addition, CommScope\u2019s expertise in security ensures that DAC private keys never leave devices and are securely stored within STM32WBA5x. This best practice enables device manufacturers to achieve IoT Device Security certification swiftly. Put simply, it removes a lot of complexity so engineers can focus on what they do best: develop unique features and release products ahead of everyone else.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of Matter development\u2019s biggest issues is a potentially false sense of security resulting from improperly implementing specifications. According to CommScope, a member of the ST Partner Program, failing to manage certificates or device attestation credentials (DACs) correctly can lead to security vulnerabilities, as DACs are the most sensitive parameters for establishing device authentication and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":78811,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[8,284,89],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v15.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CommScope PKI Center&#x2122;: An ally on the path to the IoT Device Security certification and production for Matter products - Electronics Maker<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blog.st.com\/commscope\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CommScope PKI Center&#x2122;: An ally on the path to the IoT Device Security certification and production for Matter products - Electronics Maker\" \/>\n<meta property=\"og:description\" content=\"One of Matter development\u2019s biggest issues is a potentially false sense of security resulting from improperly implementing specifications. According to CommScope, a member of the ST Partner Program, failing to manage certificates or device attestation credentials (DACs) correctly can lead to security vulnerabilities, as DACs are the most sensitive parameters for establishing device authentication and [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/blog.st.com\/commscope\/\" \/>\n<meta property=\"og:site_name\" content=\"Electronics Maker\" \/>\n<meta property=\"article:published_time\" content=\"2024-09-06T04:27:33+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-06T04:27:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/Featured-image-1140x489-20.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"600\" \/>\n\t<meta property=\"og:image:height\" content=\"257\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\">\n\t<meta name=\"twitter:data1\" content=\"Electronics Maker\">\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data2\" content=\"5 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebSite\",\"@id\":\"https:\/\/electronicsmaker.com\/#website\",\"url\":\"https:\/\/electronicsmaker.com\/\",\"name\":\"Electronics Maker\",\"description\":\"Electronics Magazine\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/electronicsmaker.com\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/blog.st.com\/commscope\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/electronicsmaker.com\/wp-content\/uploads\/2024\/09\/Featured-image-1140x489-20.jpg\",\"width\":600,\"height\":257},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/blog.st.com\/commscope\/#webpage\",\"url\":\"https:\/\/blog.st.com\/commscope\/\",\"name\":\"CommScope PKI Center&#x2122;: An ally on the path to the IoT Device Security certification and production for Matter products - Electronics Maker\",\"isPartOf\":{\"@id\":\"https:\/\/electronicsmaker.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/blog.st.com\/commscope\/#primaryimage\"},\"datePublished\":\"2024-09-06T04:27:33+00:00\",\"dateModified\":\"2024-09-06T04:27:36+00:00\",\"author\":{\"@id\":\"https:\/\/electronicsmaker.com\/#\/schema\/person\/df9e9cfbf590f29e49716824dd7d81f9\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/blog.st.com\/commscope\/\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/electronicsmaker.com\/#\/schema\/person\/df9e9cfbf590f29e49716824dd7d81f9\",\"name\":\"Electronics Maker\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/electronicsmaker.com\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a4af77a4fcb00c5dfc7c1ca124a492b4?s=96&d=mm&r=g\",\"caption\":\"Electronics Maker\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/posts\/78809"}],"collection":[{"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/comments?post=78809"}],"version-history":[{"count":1,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/posts\/78809\/revisions"}],"predecessor-version":[{"id":78813,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/posts\/78809\/revisions\/78813"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/media\/78811"}],"wp:attachment":[{"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/media?parent=78809"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/categories?post=78809"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/electronicsmaker.com\/wp-json\/wp\/v2\/tags?post=78809"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}