SlideShare ist ein Scribd-Unternehmen logo
1 von 15
May 1, 2013
Open Source Compliance in
Embedded Systems
Eli Greenbaum
Yigal Arnon & Co.
elig@arnon.co.il
May 1, 2013
May 1, 2013
Embedded Devices
• Network devices (Router, DSL Modem)
• Mobile Phones
• Televisions
• STBs, Digital Media Players
• Automobiles
• Aircraft
May 1, 2013
The BusyBox Cases
2007: Erik Anderson and Rob Landley vs.
Monsoon Media, Inc.
(Hava products, time and place shifting)
May 1, 2013
Busybox
• “Swiss Army Knife” of embedded Linux
• Lightweight set of standard utilities
• Optimized for smaller computing platforms
• Licensed under GPLv2
May 1, 2013
General Public License (GPL)
• Most popular open source license
• Depends on copyright
• Licensee can use, modify and distribute so long as:
- source code is also provided
- the GPL always applies
• Philosophy is to preserve the freedom of the user to
modify the software and run modified versions.
May 1, 2013
General Public License (GPL)
• Licensee must provide source code upon any
distribution, including
- distribution of a physical device with
software embedded in flash
- download of firmware update
- even if software was not modified
• Derivative works
May 1, 2013
Monsoon Media Claims
• Brought by BusyBox developers
• BusyBox is licensed under version 2 of the GPL
• BusyBox was included in firmware of Monsoon Media’s device
• Device was distributed without the BusyBox source code or a
written offer to receive source code.
• Copyright holders seek damages, litigation costs, injunction
against further use of the BusyBox software
May 1, 2013
2007: High Gain Antennas, LLC
(wireless router)
Xterasys Corp
(networking products)
Verizon Communications
(Actiontec Wireless Routers)
2008: Bell Microproducts
(Network attached storage device)
Super Micro Computer
(IPMI card)
May 1, 2013
2009: Best Buy (Blu-ray DVD player)
Samsung (HDTV)
Westinghouse (HDTV)
JVC (HDTV and network camera)
Western Digital (Media player)
Robert Bosch (Security system DVR)
Phoebe Micro (Wireless routers)
Humax (HDTV DVR)
Comtrend (ADSL modems)
Dobbs-Stanford (Digital media player)
Versa Technology (Outdoor WAP)
Zyxel (ADSL router)
Astak (Security camera system)
GCI (Digital music controller)
May 1, 2013
#1: Supply Chain
• SoC manufacturer
• ODM building circuit board
• SDK for SoC/board
• Application programs
• OEM selling product to end users
• Distributors/Retailers
May 1, 2013
#2: Build Scripts
• Source code includes:
“ scripts used to control compilation and
installation of the executable” (GPLv2); or
“all the source code needed to generate,
install, and … run the object code and to
modify the work, including scripts to
control those activities” (GPLv3)
May 1, 2013
#3: Installation Information
• Express requirement in GPLv3
• DRM to prevent users from running modified
versions of the software
• Cryptographic checks
of the bootloader or kernel
May 1, 2013
ComplianceTechnical
• USE open source software
• License compliance is a management and
engineering problem
• License compliance is relatively easy if done
during development
• Have a compliance policy!
May 1, 2013
Legal Compliance
• Warranties
• Indemnification
- Verizon was indemnified by Actiontec.
- Actiontec assumed obligations of the
settlement
• Due Diligence for both suppliers and OEMs
May 1, 2013
Open Source Compliance in
Embedded Systems
Eli Greenbaum
Yigal Arnon & Co.
elig@arnon.co.il
May 1, 2013

Weitere ähnliche Inhalte

Ähnlich wie TRACK B: Open source compliance in embedded systems/ Eli Greenbaum

889448 634356855122132416
889448 634356855122132416889448 634356855122132416
889448 634356855122132416
zxdrtyu
 
Vijay android ppt
Vijay android pptVijay android ppt
Vijay android ppt
vijaymashre
 
Android – Open source mobile OS developed ny the Open Handset Alliance led by...
Android – Open source mobile OS developed ny the Open Handset Alliance led by...Android – Open source mobile OS developed ny the Open Handset Alliance led by...
Android – Open source mobile OS developed ny the Open Handset Alliance led by...
jeronimored
 

Ähnlich wie TRACK B: Open source compliance in embedded systems/ Eli Greenbaum (20)

Android intro
Android introAndroid intro
Android intro
 
6 Months Industrial Training in Android
6 Months Industrial Training in Android6 Months Industrial Training in Android
6 Months Industrial Training in Android
 
6 Months Industrial Training in Big Data in Chandigarh
6 Months Industrial Training in Big Data in Chandigarh6 Months Industrial Training in Big Data in Chandigarh
6 Months Industrial Training in Big Data in Chandigarh
 
Synapseindia android apps intro to android and i os
Synapseindia android apps intro to android and i osSynapseindia android apps intro to android and i os
Synapseindia android apps intro to android and i os
 
Maddy android
Maddy androidMaddy android
Maddy android
 
Android and android phones
Android and android phonesAndroid and android phones
Android and android phones
 
Droidcon 2013 france - The Growth of Android in Embedded Systems
Droidcon 2013 france - The Growth of Android in Embedded SystemsDroidcon 2013 france - The Growth of Android in Embedded Systems
Droidcon 2013 france - The Growth of Android in Embedded Systems
 
889448 634356855122132416
889448 634356855122132416889448 634356855122132416
889448 634356855122132416
 
Synapse india reviews on android and ios
Synapse india reviews on android and iosSynapse india reviews on android and ios
Synapse india reviews on android and ios
 
Android
AndroidAndroid
Android
 
Android 1
Android 1 Android 1
Android 1
 
Android intro
Android introAndroid intro
Android intro
 
Android Seminar Presentation [March 2019]
Android Seminar Presentation [March 2019]Android Seminar Presentation [March 2019]
Android Seminar Presentation [March 2019]
 
Vijay android ppt
Vijay android pptVijay android ppt
Vijay android ppt
 
Android – Open source mobile OS developed ny the Open Handset Alliance led by...
Android – Open source mobile OS developed ny the Open Handset Alliance led by...Android – Open source mobile OS developed ny the Open Handset Alliance led by...
Android – Open source mobile OS developed ny the Open Handset Alliance led by...
 
Androids
AndroidsAndroids
Androids
 
Aplit-Soft
Aplit-Soft Aplit-Soft
Aplit-Soft
 
Android and ios app development company- thorsignia
Android and ios app development company- thorsigniaAndroid and ios app development company- thorsignia
Android and ios app development company- thorsignia
 
The MRAA and UPM Middleware Libraries
The MRAA and UPM Middleware LibrariesThe MRAA and UPM Middleware Libraries
The MRAA and UPM Middleware Libraries
 
Managed Services for the New Millennium - J Barr
Managed Services for the New Millennium - J BarrManaged Services for the New Millennium - J Barr
Managed Services for the New Millennium - J Barr
 

Mehr von chiportal

Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
chiportal
 

Mehr von chiportal (20)

Prof. Zhihua Wang, Tsinghua University, Beijing, China
Prof. Zhihua Wang, Tsinghua University, Beijing, China Prof. Zhihua Wang, Tsinghua University, Beijing, China
Prof. Zhihua Wang, Tsinghua University, Beijing, China
 
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
 
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
Prof. Steve Furber, University of Manchester, Principal Designer of the BBC M...
 
Prof. Uri Weiser,Technion
Prof. Uri Weiser,TechnionProf. Uri Weiser,Technion
Prof. Uri Weiser,Technion
 
Ken Liao, Senior Associate VP, Faraday
Ken Liao, Senior Associate VP, FaradayKen Liao, Senior Associate VP, Faraday
Ken Liao, Senior Associate VP, Faraday
 
Prof. Danny Raz, Director, Bell Labs Israel, Nokia
 Prof. Danny Raz, Director, Bell Labs Israel, Nokia  Prof. Danny Raz, Director, Bell Labs Israel, Nokia
Prof. Danny Raz, Director, Bell Labs Israel, Nokia
 
Marco Casale-Rossi, Product Mktg. Manager, Synopsys
Marco Casale-Rossi, Product Mktg. Manager, SynopsysMarco Casale-Rossi, Product Mktg. Manager, Synopsys
Marco Casale-Rossi, Product Mktg. Manager, Synopsys
 
Dr.Efraim Aharoni, ESD Leader, TowerJazz
Dr.Efraim Aharoni, ESD Leader, TowerJazzDr.Efraim Aharoni, ESD Leader, TowerJazz
Dr.Efraim Aharoni, ESD Leader, TowerJazz
 
Eddy Kvetny, System Engineering Group Leader, Intel
Eddy Kvetny, System Engineering Group Leader, IntelEddy Kvetny, System Engineering Group Leader, Intel
Eddy Kvetny, System Engineering Group Leader, Intel
 
Dr. John Bainbridge, Principal Application Architect, NetSpeed
 Dr. John Bainbridge, Principal Application Architect, NetSpeed  Dr. John Bainbridge, Principal Application Architect, NetSpeed
Dr. John Bainbridge, Principal Application Architect, NetSpeed
 
Xavier van Ruymbeke, App. Engineer, Arteris
Xavier van Ruymbeke, App. Engineer, ArterisXavier van Ruymbeke, App. Engineer, Arteris
Xavier van Ruymbeke, App. Engineer, Arteris
 
Asi Lifshitz, VP R&D, Vtool
Asi Lifshitz, VP R&D, VtoolAsi Lifshitz, VP R&D, Vtool
Asi Lifshitz, VP R&D, Vtool
 
Zvika Rozenshein,General Manager, EngineeringIQ
Zvika Rozenshein,General Manager, EngineeringIQZvika Rozenshein,General Manager, EngineeringIQ
Zvika Rozenshein,General Manager, EngineeringIQ
 
Lewis Chu,Marketing Director,GUC
Lewis Chu,Marketing Director,GUC Lewis Chu,Marketing Director,GUC
Lewis Chu,Marketing Director,GUC
 
Kunal Varshney, VLSI Engineer, Open-Silicon
Kunal Varshney, VLSI Engineer, Open-SiliconKunal Varshney, VLSI Engineer, Open-Silicon
Kunal Varshney, VLSI Engineer, Open-Silicon
 
Gert Goossens,Sen. Director, ASIP Tools, Synopsys
Gert Goossens,Sen. Director, ASIP Tools, SynopsysGert Goossens,Sen. Director, ASIP Tools, Synopsys
Gert Goossens,Sen. Director, ASIP Tools, Synopsys
 
Tuvia Liran, Director of VLSI, Nano Retina
Tuvia Liran, Director of VLSI, Nano RetinaTuvia Liran, Director of VLSI, Nano Retina
Tuvia Liran, Director of VLSI, Nano Retina
 
Sagar Kadam, Lead Software Engineer, Open-Silicon
Sagar Kadam, Lead Software Engineer, Open-SiliconSagar Kadam, Lead Software Engineer, Open-Silicon
Sagar Kadam, Lead Software Engineer, Open-Silicon
 
Ronen Shtayer,Director of ASG Operations & PMO, NXP Semiconductor
Ronen Shtayer,Director of ASG Operations & PMO, NXP SemiconductorRonen Shtayer,Director of ASG Operations & PMO, NXP Semiconductor
Ronen Shtayer,Director of ASG Operations & PMO, NXP Semiconductor
 
Prof. Emanuel Cohen, Technion
Prof. Emanuel Cohen, TechnionProf. Emanuel Cohen, Technion
Prof. Emanuel Cohen, Technion
 

Kürzlich hochgeladen

Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Kürzlich hochgeladen (20)

HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...Workshop - Best of Both Worlds_ Combine  KG and Vector search for  enhanced R...
Workshop - Best of Both Worlds_ Combine KG and Vector search for enhanced R...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot TakeoffStrategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
Strategize a Smooth Tenant-to-tenant Migration and Copilot Takeoff
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 

TRACK B: Open source compliance in embedded systems/ Eli Greenbaum

  • 1. May 1, 2013 Open Source Compliance in Embedded Systems Eli Greenbaum Yigal Arnon & Co. elig@arnon.co.il May 1, 2013
  • 2. May 1, 2013 Embedded Devices • Network devices (Router, DSL Modem) • Mobile Phones • Televisions • STBs, Digital Media Players • Automobiles • Aircraft
  • 3. May 1, 2013 The BusyBox Cases 2007: Erik Anderson and Rob Landley vs. Monsoon Media, Inc. (Hava products, time and place shifting)
  • 4. May 1, 2013 Busybox • “Swiss Army Knife” of embedded Linux • Lightweight set of standard utilities • Optimized for smaller computing platforms • Licensed under GPLv2
  • 5. May 1, 2013 General Public License (GPL) • Most popular open source license • Depends on copyright • Licensee can use, modify and distribute so long as: - source code is also provided - the GPL always applies • Philosophy is to preserve the freedom of the user to modify the software and run modified versions.
  • 6. May 1, 2013 General Public License (GPL) • Licensee must provide source code upon any distribution, including - distribution of a physical device with software embedded in flash - download of firmware update - even if software was not modified • Derivative works
  • 7. May 1, 2013 Monsoon Media Claims • Brought by BusyBox developers • BusyBox is licensed under version 2 of the GPL • BusyBox was included in firmware of Monsoon Media’s device • Device was distributed without the BusyBox source code or a written offer to receive source code. • Copyright holders seek damages, litigation costs, injunction against further use of the BusyBox software
  • 8. May 1, 2013 2007: High Gain Antennas, LLC (wireless router) Xterasys Corp (networking products) Verizon Communications (Actiontec Wireless Routers) 2008: Bell Microproducts (Network attached storage device) Super Micro Computer (IPMI card)
  • 9. May 1, 2013 2009: Best Buy (Blu-ray DVD player) Samsung (HDTV) Westinghouse (HDTV) JVC (HDTV and network camera) Western Digital (Media player) Robert Bosch (Security system DVR) Phoebe Micro (Wireless routers) Humax (HDTV DVR) Comtrend (ADSL modems) Dobbs-Stanford (Digital media player) Versa Technology (Outdoor WAP) Zyxel (ADSL router) Astak (Security camera system) GCI (Digital music controller)
  • 10. May 1, 2013 #1: Supply Chain • SoC manufacturer • ODM building circuit board • SDK for SoC/board • Application programs • OEM selling product to end users • Distributors/Retailers
  • 11. May 1, 2013 #2: Build Scripts • Source code includes: “ scripts used to control compilation and installation of the executable” (GPLv2); or “all the source code needed to generate, install, and … run the object code and to modify the work, including scripts to control those activities” (GPLv3)
  • 12. May 1, 2013 #3: Installation Information • Express requirement in GPLv3 • DRM to prevent users from running modified versions of the software • Cryptographic checks of the bootloader or kernel
  • 13. May 1, 2013 ComplianceTechnical • USE open source software • License compliance is a management and engineering problem • License compliance is relatively easy if done during development • Have a compliance policy!
  • 14. May 1, 2013 Legal Compliance • Warranties • Indemnification - Verizon was indemnified by Actiontec. - Actiontec assumed obligations of the settlement • Due Diligence for both suppliers and OEMs
  • 15. May 1, 2013 Open Source Compliance in Embedded Systems Eli Greenbaum Yigal Arnon & Co. elig@arnon.co.il May 1, 2013