Back to blog
dns Published: AEU DNS Newsroom

New IRTF Draft Maps Trust Anchors and Manufacturer-Installed Keys for Smarter Device Security

An IRTF draft now in its 14th iteration offers a taxonomy for understanding how trust is built into IoT devices, from factory-installed keys to the global DNSSEC trust anchor.

A new draft from the Internet Research Task Force (IRTF) aims to give device makers and security professionals clearer language for discussing how trust is built into the gadgets we use every day. The document, now in its 14th iteration, is by Michael Richardson and is called 'A Taxonomy of operational security considerations for manufacturer-installed keys and Trust Anchors'. It belongs to the IRTF's 'thing to thing' (t2trg) research group, which focuses on how devices communicate directly with each other. As an IRTF draft, it explicitly is not an official position of the Internet Engineering Task Force (IETF) or the IRTF; the text notes it has no formal standing in the IETF standards process. That is normal for the IRTF, a venue where speculative, forward-looking ideas are explored before they become protocol standards.

The draft is a taxonomy, meaning it sorts and names concepts. Richardson categorizes what he calls the security bootstrapping space. Bootstrapping here means the initial process of loading the first trusted software and keys into a device when it starts. Many Internet of Things (IoT) devices, such as smart cameras, local file servers, or TV control boxes, depend on a central manager run by the manufacturer and reachable through a website. This design forces the device to send everything it measures, monitors, or controls out to the cloud, outside the local home or office network. If instead devices were designed to bootstrap their security locally from the first time they are switched on, it would improve trust in their configuration and operation. Local bootstrapping allows the use of cryptographic controls without relying on third-party coordination.

At the heart of this model is the Trust Anchor (TA). A Trust Anchor is the single piece of information that is trusted by default, and it is used to verify all other claims about secure communication and device state. Richardson's draft stresses that the most important question is where your Trust Anchor comes from: who controls it, how did it get onto the device, and how can you manage it. The document also reviews related concepts including trusted zones, trusted auxiliary processors, trusted key stores, and cold boot trusted execution environments. Each influences how a device can derive a sense of trust from the factory.

A surprisingly large number of devices now include a secure sub-zone inside the main Central Processing Unit (CPU) chip. Manufactured using Very Large Scale Integration (VLSI) techniques, these sub-zones operate separately from the main processor and often limit exposure of the most sensitive device keys. Android phones, Apple devices, and laptops from many manufacturers now contain such secure units, which can protect the keying information inside the secure zone from all but state-actor levels of intrusion. Some VLSI designs even discharge electricity when someone tries to probe the chip, destroying the keys before they can be read. These protections are aligned with U.S. Federal Information Processing Standards (FIPS) guidelines, against which FIPS-certified Hardware Security Modules (HSMs) are designed and tested.

This work matters beyond individual gadgets because the same trust anchor concepts underpin the global Domain Name System (DNS). The Internet Assigned Numbers Authority (IANA) depends on FIPS-certified HSMs to operate the Trust Anchor of the global DNS, which enables DNSSEC operation worldwide. DNSSEC adds a layer of authentication to DNS, ensuring that the answer you get for a website address is the real one and not one inserted by an attacker. For readers who run websites or manage networks, the draft offers a useful way to understand secure devices and secure protocol thinking, with pointers into IETF documents on security and functional standards. Choosing an encrypted DNS service such as AEU DNS, which protects your DNS queries from interception, is a practical step that aligns with the same trust model described in the draft; for the strongest protection, pair it with a resolver that performs DNSSEC validation.

Terms explained

IRTF
Internet Research Task Force, a group that explores long-term internet research questions before they become formal standards.
IETF
Internet Engineering Task Force, the main standards body that develops the technical protocols used on the internet.
Trust Anchor
A piece of cryptographic information that is trusted by default and used to verify everything else in a security system.
IoT
Internet of Things, everyday physical devices connected to the internet such as smart bulbs, cameras, and thermostats.
DNSSEC
Domain Name System Security Extensions, a set of checks that ensure the website address you type in is the real one and not a fake.
FIPS
Federal Information Processing Standards, U.S. government security guidelines for hardware and software.
HSM
Hardware Security Module, a physical device that safely stores and manages digital keys and performs encryption operations.
VLSI
Very Large Scale Integration, the process of packing millions of tiny electronic circuits onto a single chip.

How to protect yourself

  1. Change the default password on every internet-connected device in your home, like cameras or smart plugs, to a unique, strong password.
  2. Check your router settings and turn on automatic updates so your devices always get the latest security fixes.
  3. Use a private, encrypted DNS service on your router or devices to stop your internet provider or others on the network from seeing which websites you visit.
  4. If you have many smart home gadgets, put them on a separate guest Wi-Fi network to keep them away from your main computers and files.
  5. Look for devices that advertise a hardware security module or secure element when you buy new smart home gear, because that helps protect the secret keys inside.
  6. Turn on DNSSEC validation in your router or DNS settings if available, which verifies that website addresses have not been tampered with.

Source: blog.apnic.net

Get private, encrypted DNS