Loading…
Attending this event?
October 28-29, 2024 | Tokyo, Japan
View More Details & Registration
Note: The schedule is subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit + AI_dev Japan 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

This schedule is automatically displayed in Japan Standard Time (UTC +9). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.
Embedded IoT Summit clear filter
arrow_back View All Dates
Tuesday, October 29
 

14:00 JST

Lessons Learned on Following Security Best Practices in Zephyr - Kate Stewart, The Linux Foundation
Tuesday October 29, 2024 14:00 - 14:40 JST
When the Zephyr project(https://zephyrproject.org/) launched in 2016, the lack of standardized security best practices in the IoT market segment was a known problem. It was one of the goals the project wanted to address, and started working on from before day 1. This talk will go through the journey of the last 8 years of applying known best security practices to an open source project, including becoming a CVE Numbering Authority, and forming a PSIRT team from volunteers from different companies. This team has been managing embargo windows, bulk vulnerability reports as well as the occasional vulnerability reported from the community. It is possible for open source projects to follow Security Best Practices and this talk will let others leverage the key lessons that Zephyr has learned over time.
Speakers
avatar for Kate Stewart

Kate Stewart

VP Dependable Embedded Systems, Linux Foundation
Kate Stewart works with the safety, security and license compliance communities to advance the adoption of best practices into embedded open source projects. Since joining The Linux Foundation, she has launched the ELISA and Zephyr Projects, as well as supporting other embedded projects... Read More →
Tuesday October 29, 2024 14:00 - 14:40 JST
Meeting Room 1

14:50 JST

Secure and Encrypted Boot in Zephyr RTOS - Parthiban N, Linumiz
Tuesday October 29, 2024 14:50 - 15:30 JST
MCUboot enables secure booting of Zephyr RTOS using asymmetric cryptographic signature verification with a public key. Typically, the hash of the public key is embedded within the MCUboot binary, ensuring its integrity. For enhanced tamper protection, this hash can also be securely stored and retrieved using hardware keys. Embedded SoCs, such as the i.MX RT, offer advanced security features like High Assurance Boot (HAB), Data Co-Processor (DCP), and Trusted Firmware-M (TF-M) for implementing TrustZone in SoCs like the nRF91. These features enable secure storage with hardware crypto acceleration or external security modules (e.g., TPM, EdgeLock) to store keys in a hardware vault. This presentation will explore MCUboot secure booting with hardware keys, using the NXP i.MX RT as an example. We'll delve into HAB for booting signed and encrypted MCUboot, establishing a hardware root of trust, and booting Zephyr RTOS using keys from OTP for verification. Additionally, we'll discuss using the TF-M backend and OTP for securely booting TrustZone-enabled SoCs.
Speakers
avatar for Parthiban

Parthiban

Engineer, Linumiz
With over 14 years of experience in software engineering, Parthiban founded Linumiz, a company that provides domain-neutral software services for U-Boot, Linux, and Zephyr, ranging from board bringup, board supported package, customization, device drivers, to over the air software... Read More →
Tuesday October 29, 2024 14:50 - 15:30 JST
Meeting Room 1

15:50 JST

Secure and Efficient Sensing Applications with Wasm: Sony's Edge Virtualization Platform (EVP) - Dan Mihai Dumitriu, Midokura (Sony Group)
Tuesday October 29, 2024 15:50 - 16:30 JST
In this talk, we will introduce Sony's Edge Virtualization Platform (EVP), a cutting-edge solution that leverages WebAssembly (Wasm) at the edge to ensure the security and safety of sensing applications. The EVP addresses key challenges in the embedded IoT landscape, including resource constraints, cybersecurity, and lifecycle management. Our discussion will cover: WebAssembly at the Edge: How Wasm enhances security and performance for sensing applications. Edge App SDK: A powerful toolkit for developers to create, manage, and deploy edge applications within a Wasm sandbox, ensuring compatibility and efficiency across diverse hardware. Device and Lifecycle Management: Techniques for efficient device management and application lifecycle management within the EVP. By the time of the Open Source Summit Japan, all these components will be open-sourced, aligning with Sony's upstream strategy to foster collaboration and innovation in the IoT community.
Speakers
avatar for Dan Mihai Dumitriu

Dan Mihai Dumitriu

Cto, Midokura
Dan Mihai Dumitriu is CTO of Midokura, a Sony Group company, leading an R&D team for advanced development of edge computing and AI technologies. He has deep technical insight into complex distributed systems, data center networks, and software architecture. Earlier in his career Dan... Read More →
Tuesday October 29, 2024 15:50 - 16:30 JST
Meeting Room 1

16:40 JST

Device Management and Delta Update for Embedded Devices with SWUpdate and TUF - Koshiro Onuki, Toshiba Corporation
Tuesday October 29, 2024 16:40 - 17:20 JST
Secure and efficient software updates are crucial in infrastructure. Our research integrates SWUpdate with The Update Framework (TUF), which enhances security by ensuring update integrity and improving resistance to well-known attacks. However, there are challenges in the TUF verification process for embedded devices. It requires downloading the entire target images and verifying its size and hash values. This process may be difficult to execute on devices with limited resources. Therefore, we have developed a device management function that manages unique information such as device version information, in addition to integrating with TUF. This function enables the generation of delta update images considering the target device information. As a result, it is believed that updates can be made even within limited resources by transmitting only delta. Furthermore, it becomes possible to meet specific needs of each device, such as reducing bandwidth and update time, customizing update images, and enhancing image encryption. In this presentation, we will showcase the practical implementation of our function that integrates TUF and delta update.
Speakers
avatar for Koshiro Onuki

Koshiro Onuki

Engineer, Toshiba Corporation
Koshiro Onuki has been working as a Software Engineer at TOSHIBA Corporation since 2022. His main role is to develop Linux for various industrial embedded products. He is mainly involved in research and development of software updates.
Tuesday October 29, 2024 16:40 - 17:20 JST
Meeting Room 1
 
  • Filter By Date
  • Filter By Venue
  • Filter By Type
  • Audience
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -