MAXREFDES143#: DeepCover Embedded Security in IoT Authenticated Sensing & Notification

Dependencies:   MaximInterface mbed

The MAXREFDES143# is an Internet of Things (IoT) embedded security reference design, built to protect an industrial sensing node by means of authentication and notification to a web server. The hardware includes a peripheral module representing a protected sensor node monitoring operating temperature and remaining life of a filter (simulated through ambient light sensing) and an mbed shield representing a controller node responsible for monitoring one or more sensor nodes. The design is hierarchical with each controller node communicating data from connected sensor nodes to a web server that maintains a centralized log and dispatches notifications as necessary. The mbed shield contains a Wi-Fi module, a DS2465 coprocessor with 1-Wire® master function, an LCD, LEDs, and pushbuttons. The protected sensor node contains a DS28E15 authenticator, a DS7505 temperature sensor, and a MAX44009 light sensor. The mbed shield communicates to a web server by the onboard Wi-Fi module and to the protected sensor node with I2C and 1-Wire. The MAXREFDES143# is equipped with a standard shield connector for immediate testing using an mbed board such as the MAX32600MBED#. The simplicity of this design enables rapid integration into any star-topology IoT network requiring the heightened security with low overhead provided by the SHA-256 symmetric-key algorithm.

More information about the MAXREFDES143# is available on the Maxim Integrated website.

Committer:
IanBenzMaxim
Date:
Fri Jan 19 10:33:16 2018 -0600
Revision:
35:3d414ba9ab6c
Parent:
32:0a09505a656d
Updated MaximInterface revision.

Who changed what in which revision?

UserRevisionLine numberNew contents of line
IanBenzMaxim 1:e1c7c1c636af 1 /*******************************************************************************
IanBenzMaxim 1:e1c7c1c636af 2 * Copyright (C) 2016 Maxim Integrated Products, Inc., All Rights Reserved.
IanBenzMaxim 1:e1c7c1c636af 3 *
IanBenzMaxim 1:e1c7c1c636af 4 * Permission is hereby granted, free of charge, to any person obtaining a
IanBenzMaxim 1:e1c7c1c636af 5 * copy of this software and associated documentation files (the "Software"),
IanBenzMaxim 1:e1c7c1c636af 6 * to deal in the Software without restriction, including without limitation
IanBenzMaxim 1:e1c7c1c636af 7 * the rights to use, copy, modify, merge, publish, distribute, sublicense,
IanBenzMaxim 1:e1c7c1c636af 8 * and/or sell copies of the Software, and to permit persons to whom the
IanBenzMaxim 1:e1c7c1c636af 9 * Software is furnished to do so, subject to the following conditions:
IanBenzMaxim 1:e1c7c1c636af 10 *
IanBenzMaxim 1:e1c7c1c636af 11 * The above copyright notice and this permission notice shall be included
IanBenzMaxim 1:e1c7c1c636af 12 * in all copies or substantial portions of the Software.
IanBenzMaxim 1:e1c7c1c636af 13 *
IanBenzMaxim 1:e1c7c1c636af 14 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
IanBenzMaxim 1:e1c7c1c636af 15 * OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
IanBenzMaxim 1:e1c7c1c636af 16 * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
IanBenzMaxim 1:e1c7c1c636af 17 * IN NO EVENT SHALL MAXIM INTEGRATED BE LIABLE FOR ANY CLAIM, DAMAGES
IanBenzMaxim 1:e1c7c1c636af 18 * OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
IanBenzMaxim 1:e1c7c1c636af 19 * ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR
IanBenzMaxim 1:e1c7c1c636af 20 * OTHER DEALINGS IN THE SOFTWARE.
IanBenzMaxim 1:e1c7c1c636af 21 *
IanBenzMaxim 1:e1c7c1c636af 22 * Except as contained in this notice, the name of Maxim Integrated
IanBenzMaxim 1:e1c7c1c636af 23 * Products, Inc. shall not be used except as stated in the Maxim Integrated
IanBenzMaxim 1:e1c7c1c636af 24 * Products, Inc. Branding Policy.
IanBenzMaxim 1:e1c7c1c636af 25 *
IanBenzMaxim 1:e1c7c1c636af 26 * The mere transfer of this software does not imply any licenses
IanBenzMaxim 1:e1c7c1c636af 27 * of trade secrets, proprietary technology, copyrights, patents,
IanBenzMaxim 1:e1c7c1c636af 28 * trademarks, maskwork rights, or any other form of intellectual
IanBenzMaxim 1:e1c7c1c636af 29 * property whatsoever. Maxim Integrated Products, Inc. retains all
IanBenzMaxim 1:e1c7c1c636af 30 * ownership rights.
IanBenzMaxim 32:0a09505a656d 31 *******************************************************************************/
IanBenzMaxim 1:e1c7c1c636af 32
IanBenzMaxim 32:0a09505a656d 33 #include <I2C.h>
IanBenzMaxim 32:0a09505a656d 34 #include <MaximInterface/Devices/DS2465.hpp>
IanBenzMaxim 32:0a09505a656d 35 #include <MaximInterface/Links/RomCommands.hpp>
IanBenzMaxim 32:0a09505a656d 36 #include <MaximInterface/Platforms/mbed/Sleep.hpp>
IanBenzMaxim 1:e1c7c1c636af 37 #include "SensorNode.hpp"
IanBenzMaxim 25:37ea43ff81be 38 #include "SensorData.hpp"
IanBenzMaxim 1:e1c7c1c636af 39
IanBenzMaxim 1:e1c7c1c636af 40 #ifdef TARGET_MAX32600
IanBenzMaxim 32:0a09505a656d 41 #include <max32600.h>
IanBenzMaxim 32:0a09505a656d 42 #include <clkman_regs.h>
IanBenzMaxim 32:0a09505a656d 43 #include <tpu_regs.h>
IanBenzMaxim 1:e1c7c1c636af 44 #else
IanBenzMaxim 1:e1c7c1c636af 45 #include <cstdlib>
IanBenzMaxim 1:e1c7c1c636af 46 #endif
IanBenzMaxim 1:e1c7c1c636af 47
IanBenzMaxim 32:0a09505a656d 48 using namespace MaximInterface;
IanBenzMaxim 6:b6bafd0a7013 49
IanBenzMaxim 32:0a09505a656d 50 const ManId SensorNode::manId = {0, 0};
IanBenzMaxim 1:e1c7c1c636af 51 bool SensorNode::rngInitialized = false;
IanBenzMaxim 1:e1c7c1c636af 52
IanBenzMaxim 32:0a09505a656d 53 void SensorNode::initializeRng() {
IanBenzMaxim 1:e1c7c1c636af 54 #ifdef TARGET_MAX32600
IanBenzMaxim 32:0a09505a656d 55 // Enable crypto oscillator
IanBenzMaxim 32:0a09505a656d 56 MXC_CLKMAN->clk_config |= (MXC_F_CLKMAN_CLK_CONFIG_CRYPTO_ENABLE |
IanBenzMaxim 32:0a09505a656d 57 MXC_F_CLKMAN_CLK_CONFIG_CRYPTO_RESET_N);
IanBenzMaxim 32:0a09505a656d 58 // Wait for crypto oscillator stability
IanBenzMaxim 32:0a09505a656d 59 while ((MXC_CLKMAN->intfl & MXC_F_CLKMAN_INTFL_CRYPTO_STABLE) !=
IanBenzMaxim 32:0a09505a656d 60 MXC_F_CLKMAN_INTFL_CRYPTO_STABLE);
IanBenzMaxim 32:0a09505a656d 61 // Disable crypto clock gating
IanBenzMaxim 32:0a09505a656d 62 MXC_CLKMAN->clk_ctrl |= MXC_F_CLKMAN_CLK_CTRL_CRYPTO_GATE_N;
IanBenzMaxim 32:0a09505a656d 63 // Set PRNG clock to crypto clock
IanBenzMaxim 32:0a09505a656d 64 MXC_CLKMAN->crypt_clk_ctrl_2_prng = MXC_CLKMAN->clk_ctrl_10_prng = 1;
IanBenzMaxim 32:0a09505a656d 65 // Use dynamic clock gating
IanBenzMaxim 32:0a09505a656d 66 MXC_CLKMAN->clk_gate_ctrl2 |=
IanBenzMaxim 32:0a09505a656d 67 (1 << MXC_F_CLKMAN_CLK_GATE_CTRL2_TPU_CLK_GATER_POS);
IanBenzMaxim 1:e1c7c1c636af 68 #endif
IanBenzMaxim 1:e1c7c1c636af 69 }
IanBenzMaxim 1:e1c7c1c636af 70
IanBenzMaxim 32:0a09505a656d 71 SensorNode::SensorNode(::mbed::I2C & i2c, uint8_t ds7505_i2c_addr,
IanBenzMaxim 32:0a09505a656d 72 uint8_t max44009_i2c_addr, DS2465 & ds2465)
IanBenzMaxim 32:0a09505a656d 73 : initialLux_(1), ds2465(ds2465),
IanBenzMaxim 32:0a09505a656d 74 ds28e15(MaximInterface::mbed::Sleep::instance(), ds2465, &skipRom),
IanBenzMaxim 32:0a09505a656d 75 ds7505(i2c, ds7505_i2c_addr), max44009(i2c, max44009_i2c_addr) {
IanBenzMaxim 32:0a09505a656d 76 if (!rngInitialized) {
IanBenzMaxim 1:e1c7c1c636af 77 initializeRng();
IanBenzMaxim 1:e1c7c1c636af 78 rngInitialized = true;
IanBenzMaxim 1:e1c7c1c636af 79 }
IanBenzMaxim 1:e1c7c1c636af 80 }
IanBenzMaxim 1:e1c7c1c636af 81
IanBenzMaxim 32:0a09505a656d 82 bool SensorNode::initializeSensors() {
IanBenzMaxim 32:0a09505a656d 83 return (max44009.read_current_lux(initialLux_) == MAX44009::Success);
IanBenzMaxim 1:e1c7c1c636af 84 }
IanBenzMaxim 1:e1c7c1c636af 85
IanBenzMaxim 32:0a09505a656d 86 bool SensorNode::setSecret() {
IanBenzMaxim 1:e1c7c1c636af 87 // Create constant partial secret
IanBenzMaxim 32:0a09505a656d 88 DS28E15::Scratchpad scratchpad;
IanBenzMaxim 25:37ea43ff81be 89 scratchpad.fill(uint8_t(defaultPaddingByte));
IanBenzMaxim 1:e1c7c1c636af 90 // Calculate secret
IanBenzMaxim 32:0a09505a656d 91 const Sha256::SlaveSecretData data = DS28E15::createSlaveSecretData(
IanBenzMaxim 32:0a09505a656d 92 DS28E15::Page(), authData.pageNum, scratchpad, romId_, manId);
IanBenzMaxim 32:0a09505a656d 93 return !ds2465.computeSlaveSecretWithSwap(data, 0, DS2465::FullPage);
IanBenzMaxim 1:e1c7c1c636af 94 }
IanBenzMaxim 1:e1c7c1c636af 95
IanBenzMaxim 32:0a09505a656d 96 bool SensorNode::checkProvisioned(bool & provisioned) {
IanBenzMaxim 32:0a09505a656d 97 DS28E15::BlockProtection protectionStatus;
IanBenzMaxim 1:e1c7c1c636af 98 bool result;
IanBenzMaxim 32:0a09505a656d 99
IanBenzMaxim 32:0a09505a656d 100 result = !ds28e15.readBlockProtection(0, protectionStatus);
IanBenzMaxim 32:0a09505a656d 101 if (result) {
IanBenzMaxim 32:0a09505a656d 102 if (!protectionStatus.noProtection()) {
IanBenzMaxim 32:0a09505a656d 103 result = !ds28e15.readSegment(authData.pageNum, authData.segmentNum,
IanBenzMaxim 32:0a09505a656d 104 authData.segment);
IanBenzMaxim 1:e1c7c1c636af 105 if (result)
IanBenzMaxim 1:e1c7c1c636af 106 provisioned = true;
IanBenzMaxim 32:0a09505a656d 107 } else {
IanBenzMaxim 1:e1c7c1c636af 108 provisioned = false;
IanBenzMaxim 1:e1c7c1c636af 109 }
IanBenzMaxim 1:e1c7c1c636af 110 }
IanBenzMaxim 1:e1c7c1c636af 111 return result;
IanBenzMaxim 1:e1c7c1c636af 112 }
IanBenzMaxim 1:e1c7c1c636af 113
IanBenzMaxim 32:0a09505a656d 114 bool SensorNode::checkAuthentic(unsigned int userEntropy) {
IanBenzMaxim 32:0a09505a656d 115 DS28E15::Scratchpad challenge;
IanBenzMaxim 32:0a09505a656d 116 DS28E15::Page pageData;
IanBenzMaxim 32:0a09505a656d 117
IanBenzMaxim 1:e1c7c1c636af 118 // Read page data
IanBenzMaxim 32:0a09505a656d 119 if (ds28e15.readPage(authData.pageNum, pageData))
IanBenzMaxim 1:e1c7c1c636af 120 return false;
IanBenzMaxim 32:0a09505a656d 121
IanBenzMaxim 1:e1c7c1c636af 122 // Create random challenge
IanBenzMaxim 1:e1c7c1c636af 123 // Use hardare RNG on MAX32600
IanBenzMaxim 32:0a09505a656d 124 #ifdef TARGET_MAX32600
IanBenzMaxim 1:e1c7c1c636af 125 MXC_TPU->prng_user_entropy = userEntropy;
IanBenzMaxim 1:e1c7c1c636af 126 #else
IanBenzMaxim 1:e1c7c1c636af 127 std::srand(userEntropy);
IanBenzMaxim 1:e1c7c1c636af 128 #endif
IanBenzMaxim 32:0a09505a656d 129 for (size_t i = 0; i < challenge.size(); i++) {
IanBenzMaxim 1:e1c7c1c636af 130 #ifdef TARGET_MAX32600
IanBenzMaxim 1:e1c7c1c636af 131 challenge[i] = MXC_TPU->prng_rnd_num;
IanBenzMaxim 1:e1c7c1c636af 132 #else
IanBenzMaxim 32:0a09505a656d 133 challenge[i] = std::rand();
IanBenzMaxim 1:e1c7c1c636af 134 #endif
IanBenzMaxim 1:e1c7c1c636af 135 }
IanBenzMaxim 1:e1c7c1c636af 136
IanBenzMaxim 1:e1c7c1c636af 137 // Write challenge to scratchpad
IanBenzMaxim 32:0a09505a656d 138 if (ds28e15.writeScratchpad(challenge))
IanBenzMaxim 1:e1c7c1c636af 139 return false;
IanBenzMaxim 1:e1c7c1c636af 140 // Have device compute MAC
IanBenzMaxim 32:0a09505a656d 141 Sha256::Hash nodeMac;
IanBenzMaxim 32:0a09505a656d 142 if (ds28e15.computeReadPageMac(0, false, nodeMac))
IanBenzMaxim 1:e1c7c1c636af 143 return false;
IanBenzMaxim 1:e1c7c1c636af 144 // Compute expected MAC
IanBenzMaxim 32:0a09505a656d 145 const Sha256::AuthMacData controllerMacData = DS28E15::createAuthMacData(
IanBenzMaxim 32:0a09505a656d 146 pageData, authData.pageNum, challenge, romId_, manId);
IanBenzMaxim 32:0a09505a656d 147 Sha256::Hash controllerMac;
IanBenzMaxim 32:0a09505a656d 148 if (ds2465.computeAuthMac(controllerMacData, controllerMac))
IanBenzMaxim 1:e1c7c1c636af 149 return false;
IanBenzMaxim 1:e1c7c1c636af 150 // Check if authentic
IanBenzMaxim 1:e1c7c1c636af 151 return (nodeMac == controllerMac);
IanBenzMaxim 1:e1c7c1c636af 152 }
IanBenzMaxim 1:e1c7c1c636af 153
IanBenzMaxim 32:0a09505a656d 154 bool SensorNode::readSensorData(SensorData & sensorData) {
IanBenzMaxim 1:e1c7c1c636af 155 bool result;
IanBenzMaxim 20:cdba71cb5506 156 int8_t temp;
IanBenzMaxim 32:0a09505a656d 157
IanBenzMaxim 1:e1c7c1c636af 158 // Read temperature sensor
IanBenzMaxim 1:e1c7c1c636af 159 result = (ds7505.read_current_temp(temp) == DS7505::Success);
IanBenzMaxim 32:0a09505a656d 160
IanBenzMaxim 32:0a09505a656d 161 if (result) {
IanBenzMaxim 1:e1c7c1c636af 162 sensorData.temp = temp;
IanBenzMaxim 32:0a09505a656d 163
IanBenzMaxim 1:e1c7c1c636af 164 // Read light sensor
IanBenzMaxim 1:e1c7c1c636af 165 double currentLux;
IanBenzMaxim 1:e1c7c1c636af 166 result = (max44009.read_current_lux(currentLux) == MAX44009::Success);
IanBenzMaxim 32:0a09505a656d 167 if (result) {
IanBenzMaxim 1:e1c7c1c636af 168 // Convert lux to remaining filter life
IanBenzMaxim 32:0a09505a656d 169 sensorData.filterLife =
IanBenzMaxim 32:0a09505a656d 170 static_cast<uint8_t>((currentLux / initialLux_) * 100);
IanBenzMaxim 1:e1c7c1c636af 171 }
IanBenzMaxim 1:e1c7c1c636af 172 }
IanBenzMaxim 32:0a09505a656d 173
IanBenzMaxim 1:e1c7c1c636af 174 return result;
IanBenzMaxim 1:e1c7c1c636af 175 }
IanBenzMaxim 1:e1c7c1c636af 176
IanBenzMaxim 32:0a09505a656d 177 bool SensorNode::checkAndWriteAuthData(SensorData & sensorData) {
IanBenzMaxim 1:e1c7c1c636af 178 bool result = true;
IanBenzMaxim 32:0a09505a656d 179
IanBenzMaxim 32:0a09505a656d 180 if (sensorData.filterLife > authData.filterLife()) {
IanBenzMaxim 32:0a09505a656d 181 sensorData.filterLife = authData.filterLife();
IanBenzMaxim 32:0a09505a656d 182 } else if (sensorData.filterLife < authData.filterLife()) {
IanBenzMaxim 32:0a09505a656d 183 AuthData newAuthData = authData;
IanBenzMaxim 32:0a09505a656d 184 newAuthData.filterLife() = sensorData.filterLife;
IanBenzMaxim 32:0a09505a656d 185 const Sha256::WriteMacData macData = DS28E15::createSegmentWriteMacData(
IanBenzMaxim 32:0a09505a656d 186 authData.pageNum, authData.segmentNum, newAuthData.segment,
IanBenzMaxim 32:0a09505a656d 187 authData.segment, romId_, manId);
IanBenzMaxim 32:0a09505a656d 188 Sha256::Hash mac;
IanBenzMaxim 32:0a09505a656d 189 result = !ds2465.computeWriteMac(macData, mac);
IanBenzMaxim 32:0a09505a656d 190 if (result)
IanBenzMaxim 32:0a09505a656d 191 result = !ds28e15.writeAuthSegment(authData.pageNum, authData.segmentNum,
IanBenzMaxim 32:0a09505a656d 192 newAuthData.segment, mac);
IanBenzMaxim 32:0a09505a656d 193 if (result)
IanBenzMaxim 32:0a09505a656d 194 authData = newAuthData;
IanBenzMaxim 1:e1c7c1c636af 195 }
IanBenzMaxim 32:0a09505a656d 196
IanBenzMaxim 1:e1c7c1c636af 197 return result;
IanBenzMaxim 1:e1c7c1c636af 198 }
IanBenzMaxim 1:e1c7c1c636af 199
IanBenzMaxim 32:0a09505a656d 200 SensorNode::State SensorNode::detect(unsigned int userEntropy) {
IanBenzMaxim 1:e1c7c1c636af 201 bool provisioned;
IanBenzMaxim 32:0a09505a656d 202
IanBenzMaxim 32:0a09505a656d 203 ds2465.setSpeed(DS2465::OverdriveSpeed);
IanBenzMaxim 32:0a09505a656d 204
IanBenzMaxim 32:0a09505a656d 205 if (readRom(ds2465, romId_))
IanBenzMaxim 1:e1c7c1c636af 206 return UnableToCommunicate;
IanBenzMaxim 32:0a09505a656d 207
IanBenzMaxim 1:e1c7c1c636af 208 if (!checkProvisioned(provisioned))
IanBenzMaxim 1:e1c7c1c636af 209 return UnableToCommunicate;
IanBenzMaxim 32:0a09505a656d 210
IanBenzMaxim 1:e1c7c1c636af 211 if (!provisioned)
IanBenzMaxim 32:0a09505a656d 212 return NotProvisioned;
IanBenzMaxim 32:0a09505a656d 213
IanBenzMaxim 1:e1c7c1c636af 214 if (!setSecret())
IanBenzMaxim 1:e1c7c1c636af 215 return UnableToCommunicate;
IanBenzMaxim 32:0a09505a656d 216
IanBenzMaxim 1:e1c7c1c636af 217 if (!checkAuthentic(userEntropy))
IanBenzMaxim 1:e1c7c1c636af 218 return NotAuthentic;
IanBenzMaxim 32:0a09505a656d 219
IanBenzMaxim 1:e1c7c1c636af 220 if (!initializeSensors())
IanBenzMaxim 1:e1c7c1c636af 221 return UnableToCommunicate;
IanBenzMaxim 32:0a09505a656d 222
IanBenzMaxim 1:e1c7c1c636af 223 return Authentic;
IanBenzMaxim 1:e1c7c1c636af 224 }
IanBenzMaxim 1:e1c7c1c636af 225
IanBenzMaxim 32:0a09505a656d 226 SensorNode::State
IanBenzMaxim 32:0a09505a656d 227 SensorNode::authenticatedReadSensorData(unsigned int userEntropy,
IanBenzMaxim 32:0a09505a656d 228 SensorData & sensorData) {
IanBenzMaxim 32:0a09505a656d 229 ds2465.setSpeed(DS2465::OverdriveSpeed);
IanBenzMaxim 32:0a09505a656d 230
IanBenzMaxim 1:e1c7c1c636af 231 if (!setSecret())
IanBenzMaxim 1:e1c7c1c636af 232 return UnableToCommunicate;
IanBenzMaxim 32:0a09505a656d 233
IanBenzMaxim 1:e1c7c1c636af 234 if (!checkAuthentic(userEntropy))
IanBenzMaxim 1:e1c7c1c636af 235 return NotAuthentic;
IanBenzMaxim 32:0a09505a656d 236
IanBenzMaxim 1:e1c7c1c636af 237 if (!readSensorData(sensorData))
IanBenzMaxim 1:e1c7c1c636af 238 return UnableToCommunicate;
IanBenzMaxim 32:0a09505a656d 239
IanBenzMaxim 1:e1c7c1c636af 240 if (!checkAndWriteAuthData(sensorData))
IanBenzMaxim 1:e1c7c1c636af 241 return NotAuthentic;
IanBenzMaxim 32:0a09505a656d 242
IanBenzMaxim 1:e1c7c1c636af 243 return Authentic;
IanBenzMaxim 1:e1c7c1c636af 244 }