Thursday, January 3rd 2019

USB-IF Launches USB Type-C Authentication Program

USB Implementers Forum (USB-IF), the support organization for the advancement and adoption of USB technology, today announced the launch of its USB Type-C Authentication Program, marking an important milestone for the optional USB security protocol. The USB Type-C Authentication specification defines cryptographic-based authentication for USB Type-C chargers and devices.

USB Type-C Authentication empowers host systems to protect against non-compliant USB chargers and to mitigate risks from malicious firmware/hardware in USB devices attempting to exploit a USB connection. Using this protocol, host systems can confirm the authenticity of a USB device, USB cable or USB charger, including such product aspects as the capabilities and certification status. All of this happens right at the moment a connection is made - before inappropriate power or data can be transferred.

"USB-IF is excited to launch the USB Type-C Authentication Program, providing OEMs with the flexibility to implement a security framework that best fits their specific product requirements," said USB-IF President and COO Jeff Ravencraft. "As the USB Type-C ecosystem continues to grow, companies can further provide the security that consumers have come to expect from certified USB devices."

Key characteristics of the USB Type-C Authentication solution include:
  • A standard protocol for authenticating certified USB Type-C chargers, devices, cables and power sources
  • Support for authenticating over either USB data bus or USB Power Delivery communications channels
  • Products that use the authentication protocol retain control over the security policies to be implemented and enforced
  • Relies on 128-bit security for all cryptographic methods
  • Specification references existing internationally-accepted cryptographic methods for certificate format, digital signing, hash and random number generation
USB-IF selected DigiCert to manage the PKI and certificate authority services for the USB Type-C Authentication Program. For further details, read the DigiCert announcement.

"DigiCert is excited to work with USB-IF and its CA Program Participants from the industry at large to provide the technical expertise and scale needed for the USB Type-C Authentication Program, and we look forward to implementation," said Geoffrey Noakes, Vice President, IoT Business Development at DigiCert.
Add your own comment

3 Comments on USB-IF Launches USB Type-C Authentication Program

#1
moproblems99
I have read a lot of articles about this being used for authorized accessories only. I think it is a little early to be fear mongering but we'll see.
Posted on Reply
#2
bug
USB Type-C Authentication empowers host systems to protect against non-compliant USB chargers and to mitigate risks from malicious firmware/hardware in USB devices attempting to exploit a USB connection.
It may do that, but it doesn't do it the traditional way. It doesn't check for capabilities, current or voltage. Instead it locks the whole thing down and "empowers" the host system to do the above as a side effect.
Posted on Reply
#3
moproblems99
bug, post: 3969613, member: 157434"
It may do that, but it doesn't do it the traditional way. It doesn't check for capabilities, current or voltage. Instead it locks the whole thing down and "empowers" the host system to do the above as a side effect.
Correct, the key is that it is left to the vendor to implement and not a USB-C standard. It leaves the door open for abuse and let's be honest - with today's market place, it is very likely this is how it will be used. That said, I will wait until it happens to be worried about it.
Posted on Reply