IBM bakes security into processors

Researchers at IBM have come up with a way to hardwire encryption technology into a microprocessor, promising a more secure way to store data.

IBM plans to announce availability of the new technology, dubbed Secure Blue, on Monday. The Armonk, N.Y.-based company envisions its idea and technology will be used in digital media players, electronic organizers, cell phones, computers and devices used by the government and the medical and financial industries.

With Secure Blue, data is encrypted and decrypted as it runs through a processor, according to IBM. It is maintained encrypted in the device memory, or RAM. One of the few times data would not be scrambled is when it is actually displayed.

"There is a lot of concern about leakage of data," Charles Palmer, manager security and privacy at IBM, said in an interview. "If you have an architecture where that information is always encrypted, you go a long way to protect your data."

Secure Blue requires a few circuits to be added to a microprocessor, taking up a small percentage of the overall silicon real estate, according to IBM. The encryption and decryption happens on-the-fly, without any processor overhead, the company said.

The hardwired security technology can be used for multiple purposes, not all of which necessarily serve the device owner. It can protect data when a person's computer or device is lost, stolen or hacked, for example. But content owners can also use it for enforcement of copyright, called digital rights management (DRM), which critics have called a scourge to user freedom.

"This is a technology that can solve a lot of problems," Palmer said. "It can be used for DRM, it can be used for systems management, and it can be used for protecting my information on the BlackBerry." The future will decide how it will be used. IBM on Monday is only announcing availability of the technology, Palmer noted.

The idea of hardware-based security is not new. Millions of laptops already contain a chip called a Trusted Platform Module, or TPM, which offers protected storage of encryption keys, passwords and digital certificates. The idea of the TPM is also coming to servers and mobile phones.

"The TPM is a step in the right direction," Palmer said. "But it is not a bulk encryption device, and it would probably melt if you try to use it for an encrypted anywhere capability."

IBM has built a prototype of Secure Blue using its own PowerPC processor technology. However, the system will work with any processor design, including those from Intel and Advanced Micro Devices that are used in PCs. An IBM representative said the company has not had discussions with Intel or AMD on including Secure Blue in their processors.

More from News.com on this story's topics

Security

Create an email alert | RSS feed

Mobile/wireless

Create an email alert | RSS feed

Consumer hardware

RSS feed

Authentication and encryption

Create an email alert | RSS feed

Processors

Create an email alert | RSS feed

IBM

Create an email alert | RSS feed

See more CNET content tagged:
encryption technology, IBM Corp., IBM PowerPC, microprocessor, digital-rights management

Add a Comment (Log in or register) 8 comments (Page 1 of 1)
Whos been nicking ideas?
by jatos April 10, 2006 9:45 AM PDT
Isn't a similar principle used in the XBOX 360?
Reply to this comment
Only way of getting DRM on Linux
by bugmenot April 10, 2006 9:53 AM PDT
It can't be don in software as the software and the system must remain open. Hardware decoders are the only way of getting DRM on Linux. The interface to the decoder would have to be open, and there'd have to be mechanisms for moving keys as you change platform.
Reply to this comment
Hardware Upgrades
by sauce214 April 10, 2006 10:07 AM PDT
What happens if you want to upgrade your hardware in the future or if you have a hardware failure. Will all your data that is encrypted on the hd not be accessible with a different cpu?
Reply to this comment View reply
So what does this protect against?
by Requiem April 10, 2006 10:35 AM PDT
I can see it working to stop someone reading data off the RAM chips if they got them out of the machine and into cold storage fast enough, but I can get very close to level of protection through software alone. What I wonder is, does this do anything to protect against malicious software? I suspect not, but the article does not say.
Reply to this comment
Powered by Jive Software
advertisement
RSS Feeds
Add headlines from CNET News.com to your homepage or feedreader.
Google
Yahoo
MSN
More feeds available in our RSS feed index.
Today's Top Stories
Yahoo tries to conceal lawsuit documents
Social graphs just wanna be free, but will they?
HP to launch fall line of teen-designed products
Conde Nast buys Ars Technica
Google to host 'Factory Tour' Monday morning
Most Popular Stories
Images: Microsoft telescope puts universe on your desktop
Photos: Cracking open the Atari 2600
This VC forecast scares the pants off of me
End of Intel, AMD duopoly near? Via readies Isaiah chip
Photos: Microsoft previews 2008 Xbox games
Markets

Market news, charts, SEC filings, and more

Related quotes

IBM (-0.50%) -0.64 127.82
Dow Jones Industrials (-0.05%) -5.86 12,986.80
S&P 500 (0.13%) 1.78 1,425.35
NASDAQ (-0.19%) -4.88 2,528.85
CNET TECH (0.05%) 0.88 1,783.62
  Symbol Lookup
Detroit auto show
Detroit auto show

Detroit auto show
advertisement
Click Here
On TV.com: MILEY CYRUS photographs
Advanced
search
Advanced
search
Visit other CNET Networks sites: