As more devices use USB-C for charging and data transfer, the need for improvements to the technology is becoming apparent. The USB Implementers Forum has announced (PDF) changes to USB-C authentication for increased security.
This new security feature will allow devices to certify that USB-C connections are legitimate, for both charging and data transfers.
With the upcoming technology, the device will immediately verify that a USB-C connection is indeed legitimate, and will block or allow the connection accordingly.
For example, consider wanting to charge your device at a public charging station. Currently, the risks are high. No one can know if the public charging station has been “hacked” and your data is at risk.
However, with USB C authentication, the connected device could verify whether the charging source is secure and block access to your data if it is not.
Features of the upcoming USB-C:
A standardized protocol for certifying USB Type-C chargers, devices, cables, and power sources
Support for authentication via either the USB data bus or USB Power Delivery communication channels
Products using the authentication protocol have control over the security policies that need to be implemented and will enforce them
Depending on 128-bit security for all encrypted methods
The specification lists existing internationally accepted cryptographic methods for certificate format, digital signing, hash, and random number generation
Of course, device manufacturers and operating system developers will need to include support for the new USB-C authentication.
Hopefully, most manufacturers/developers will recognize the value of the technology and include it in their devices or operating system.
___________________
- iGuRu.gr Google Group Support Forum
- FOSSA the EU funds bug bounty for 14 open source projects
- Google: forget the Google Search white page
- Windows 10 OEM product key without third-party tools
