Story image

USB regulatory body launches USB-C authentication programme

09 Jan 19

The USB Implementers Forum (USB-IF), the support organisation for the advancement and adoption of USB technology, has announced the launch of its USB Type-C Authentication Program, marking a milestone for the optional USB security protocol.

The USB Type-C Authentication specification defines cryptographic-based authentication for USB Type-C chargers and devices.

USB Type-C Authentication empowers host systems to protect against non-compliant USB chargers and to mitigate risks from malicious firmware/hardware in USB devices attempting to exploit a USB connection.

Using this protocol, host systems can confirm the authenticity of a USB device, USB cable or USB charger, including such product aspects as the capabilities and certification status.

All of this happens right at the moment a connection is made – before inappropriate power or data can be transferred.

USB-IF president and COO Jeff Ravencraft says, “USB-IF is excited to launch the USB Type-C Authentication Program, providing OEMs with the flexibility to implement a security framework that best fits their specific product requirements.”

“As the USB Type-C ecosystem continues to grow, companies can further provide the security that consumers have come to expect from certified USB devices.”

Key characteristics of the USB Type-C Authentication solution include:

  • A standard protocol for authenticating certified USB Type-C chargers, devices, cables and power sources
  • Support for authenticating over either USB data bus or USB Power Delivery communications channels
  • Products that use the authentication protocol retain control over the security policies to be implemented and enforced
  • Relies on 128-bit security for all cryptographic methods
  • Specification references existing internationally-accepted cryptographic methods for certificate format, digital signing, hash and random number generation
  • USB-IF selected DigiCert to manage the PKI and certificate authority services for the USB Type-C Authentication Program.

“DigiCert is excited to work with USB-IF and its CA Program Participants from the industry at large to provide the technical expertise and scale needed for the USB Type-C Authentication Program, and we look forward to implementation,” says DigiCert IoT and business development vice president Geoffrey Noakes.

The non-profit USB Implementers Forum was formed to provide a support organisation and forum for the advancement and adoption of USB technology as defined in the USB specifications.

USB-IF facilitates the development of high-quality compatible USB devices through its logo and compliance programme and promotes the benefits of USB and the quality of products that have passed compliance testing.

LogicMonitor launches container monitoring solutions
Kubernetes monitoring and LM Service Insight provide performance analytics and data retention for microservices and containerised applications.
InfluxData aims to accelerate growth with new sales executives
As time-based data is generated at exponential rates from increased use of DevOps and IoT sensors, companies are requiring more advanced performance tools to analyze their complex environments. 
Commvault fully integrates backup with Cisco Hyperflex
Its IntelliSnap technology has been validated to work with Cisco HyperFlex hyper-converged systems without the need for third-party tools.
Huawei continues 5G trails despite interational concern
Huawei completed the 5G NR test at 2.6GHz spectrum in the 5G trial organised by the IMT-2020 (5G) Promotion Group. 
Experts comment on record 772mil-user data breach
Dubbed “Collection #1”, the data set contains emails and passwords with over a billion unique combinations of email addresses and passwords.
McAfee Gartner Customers’ Choice for Secure Web Gateway
“We take great pride in being recognised by our customers on Gartner Peer Insights, and their willingness to recommend McAfee Web Gateway technology”
Why flexible working could make good business sense
“You can always give it a go on a trial basis. If it’s not working, be honest."
Top risk facing organisations? Why, it’s an IT talent famine
For some time there has been talk about how the IT industry is crying out for new talent and skills, which a lot of people have glossed over. But now Gartner says it is a harsh reality.