Microsoft with Azure Sphere Looks to Set Gold Standard in End-to-End IoT Security
Source: Microsoft
- Hardware: Azure Sphere embeds secure keys (public) within a secure MCU/MPU powered by its Pluton security subsystem.
- Pluton includes a security processor unit with a random number generator (RNG)
- Tamper and side-channel attack resistant
- Other cryptography and encryption tools
- Secure booting for remote attestation and certificate-based security
Source: Microsoft
- Software: Azure Sphere OS:
- Azure Sphere OS is made up of a custom Linux kernel, which runs on 2.4MB code storage, which is carefully tuned for the flash and RAM footprint of the Azure Sphere MCU to reduce its attack surface.
- The OS communicates with the Azure Sphere Security service in the cloud for secure device authentication, network management, application management for all outbound traffic.
- It undertakes secure monitoring to protect memory, flash and other MCU resources limiting exposure.
- The OS includes Microsoft-provided application runtime to restrict access to file I/O or shell access.
- It also includes a high-level application platform which is signed by Microsoft Certificate Authority (CA) through a trusted pipeline to maintain all software other than the device-specific applications.
- Cloud: Azure Sphere Security Service
- Azure Sphere Security Service brokers trust for device-to-cloud communication, detects threats, and renews device security via CA based-authentication, failure reporting and automatic updates for OS.
- Azure Sphere in the cloud thus embeds with a private key that enables asymmetric encryption and authenticates devices with paired public keys at the time of the manufacturing process.
- Further, Azure Sentinel provides cloud security through Artificial Intelligence.
The integration of all three elements enables the hardware root of trust with asymmetric encryption. Further, it creates a secure tunnel for the secure flow of data from chip to cloud ensuring both the data security at rest and in transit.
Following chart depicts Azure Sphere running on a Guardian IoT module for a brownfield IoT deployment
Source: Microsoft
Growing Partner Ecosystem:
- Chipsets:
- In 2018, ST Micro's STM32, a secure MCU embed with a secure element and integrated with Azure IoT C SDK, which enables direct and secure connectivity to the Azure IoT Hub, as well as full support for Azure device management.
- In mid-2019, NXP'sMX 8 series, integrates Microsoft's Azure Sphere security architecture and Pluton Security Subsystem.
- MediaTek MT3620 is Azure Sphere ready
- At the end of 2019, Qualcomm’s 9205 LTE multimode modem supporting both LTE-M / NB-IoT was integrated with Microsoft's Azure Sphere.
- Modules
- Avnet and qiio offer Avnet Guardian 100 and qiio q200 Guardian (add-on) modules for retrofitting on exiting brownfield devices which lack connectivity and security but need to be connected to the Internet.
- Other modules include Avnet AES-MS-MT3620, AI-Link WF-M620-RSC1 and USI Wi-Fi module with Bluetooth option.
Case Study: Starbucks Starbucks has deployed Azure Sphere across its stores in North America. Each Starbucks store has around ten to twelve pieces of equipment that are operational for more than fifteen hours a day and are needed to be connected to the cloud for beverage related data (10 to 12 data points worth 5MB generated per beverage), asset monitoring and any predictive maintenance to avoid disruptions. This is important as any equipment breakdown is directly proportional to the store’s performance, its business and customer dissatisfaction. Starbucks has therefore been using the guardian modules deployed by Azure Sphere with the help of Microsoft across all its brownfield equipment to securely connect and aggregate the data to the cloud.With this approach, Microsoft is building a highly scalable and secure approach to onboard, manage and connect IoT devices and ensure the data is securely transmitted from device to cloud. This eliminates the need for most IoT customers to hire expensive security professionals.
Source: Microsoft
Chip-to-Cloud Security is the Gold Standard Security and privacy are global concerns around IoT, irrespective of country. Security is one of the major roadblocks for IoT. However, in the past two years, we have seen the adoption of chip-to-cloud security due to an increase in awareness of the threats and its scalable solution. The end-to-end security will be critical to the success of any future IoT deployments to protect the asset as well as the data which, in most cases, is even more valuable.Receive our insightful weekly newsletter and stay ahead of the competition.
Author
Team Counterpoint
Counterpoint Research is a global industry and market research firm providing market data, intelligence, thought leadership and consulting across the technology ecosystem. We advise a diverse range of global clients spanning the supply chain – from chipmakers, component suppliers, manufacturers and software and application developers to service providers, channel players and investors. Our veteran team of analysts serve these clients through our offices located across the key innovation hubs, manufacturing clusters and commercial centers globally. Our analysts consistently engage with C-suite through to strategy, market intelligence, supply chain, R&D, product management, marketing, sales and others across the organization. Counterpoint’s key coverage areas: AI, Automotive, Cloud, Connectivity, Consumer Electronics, Displays, eSIM, IoT, Location Platforms, Macroeconomics, Manufacturing, Networks & Infra, Semiconductors, Smartphones and Wearables.