Unveiling IoT security solutions: Microsoft Azure Sphere

Publisher:EEWorld资讯Latest update time:2020-07-23 Source: EEWorld Reading articles on mobile phones Scan QR code
Read articles on your mobile phone anytime, anywhere

Azure Sphere is an end-to-end, highly secure solution for IoT devices. It was officially launched in February 2020, heralding a new era of IoT security. Recently, Microsoft Azure Sphere Chief Solution Expert Michael Yu and Microsoft IoT Architect Neo Xiong were interviewed by EEWorld to introduce what Azure Sphere has done in the security field.


Why choose Microsoft?


For most companies, security is not their expertise, so choosing a mature security solution is undoubtedly the best option. Azure Sphere was born out of such a need.


Microsoft Azure is one of the most complete cloud ecosystems in the world. 95% of the top 500 companies use Azure, and its cloud computing resources exceed the combined total of AWS and Google. Microsoft is also one of the most important suppliers of IoT service platforms, providing complete PaaS and SaaS services. In the field of security, Microsoft has more than 30 years of experience in network security and more than 10 years of experience in hardware encryption security, making it a unique cloud security leader.


In 2017, Microsoft released a security improvement model and seven characteristics of high-security devices, and other research results to promote the best practices of IoT security, including hardware root of trust deep protection, trusted computer dynamic partitioning, certificate-based authentication, fault reporting, and updateable security policies. Microsoft believes that only when these seven characteristics are possessed at the same time can it be considered highly secure. Gartner also reported that customers need to have a better understanding of security, not only device encryption, the use of secure chips, etc., but also a complete device security.


111.png

Seven safety features


A brief analysis of the three elements of Azure Sphere


Microsoft Azure Sphere is a security solution developed based on seven major features, including three elements: an MCU with a built-in security subsystem certified by Microsoft, a secure operating system, and a secure cloud service.


For the processor, Microsoft's Rock security subsystem Pluton is built in to generate and store keys, execute encryption algorithms, provide internal security partitions, and isolate them with a bus-level firewall.


222.png


As shown in the figure, Microsoft has started to cooperate with many leading chip suppliers to develop Microsoft-certified IoT MCUs, of which the first product is MediaTek MT3620. Based on Microsoft's Azure Sphere solution, Avnet has launched the Azure Sphere MT360 Starter Kit, which can build prototypes for the rapid implementation of IoT projects and quickly bring new IoT terminal devices to market. (For hardware information, please read Avnet MT3620 module accelerates the secure implementation of Azure Sphere IoT)


During the production process of each Azure Sphere chip, a pair of company keys will be generated by the internal Pluton. The public key will be transmitted to the Azure Sphere secure cloud service through a secure channel and recorded, while the private key will never leave the Pluton module, ensuring the security of the private key.


333.png


Azure Sphere's operating system has a four-layer architecture, which also takes into account security requirements such as deep protection and dynamic partitioning, thus establishing the Security Monitor layer, service layer, and container layer. The Security Monitor runs on ARM TrustZone and has full access to CPU resources. The Linux kernel tailors and optimizes IoT scenarios to make the system streamlined and efficient while reducing the attack surface. The service layer provides OTA two-way authentication, device management, firmware updates, and error report collection. At the application layer, in order to maintain API compatibility, the Azure Sphere OS team runs containers and applications and OTAs completely independently.


Cloud services ensure the security of IoT devices


In terms of security cloud services, Azure Sphere security cloud service is a SaaS service deployed on Microsoft's public cloud. Users only need to register and log in to use it directly. It mainly includes device identity authentication, device OS and application updates, and collection and reporting of abnormal device status.


In fact, Microsoft has made many more improvements to IoT security, which are not listed here one by one. If you read the instructions of Azure Sphere carefully, you will find that there are details provided everywhere to ensure security.


The Azure Sphere system is open to all MCU manufacturers, all types of clouds, development environments, and ecosystems. For this reason, Azure Sphere has won the favor of many customers. A typical example is Starbucks, which has securely connected 30,000 coffee machines around the world through Azure Sphere, carried out digital transformation, and realized equipment operation and maintenance and OTA functions of coffee machines.


At present, many Chinese partners have launched Guardian Modules for Microsoft Azure Sphere to meet the needs of secure networking of devices with multiple communication interfaces and in multiple scenarios, so that traditional devices can use Guardian Modules to achieve secure IoT access without any hardware updates.


With Microsoft's official announcement of commercial use and early adoption by many large companies, Azure Sphere has been proven to be one of the best end-to-end solutions in the field of IoT security. As Jeff Wile, senior vice president of infrastructure and operations at Starbucks, said, "Using Microsoft Azure Sphere allows Starbucks partners and employees to focus more on creating value for customers. Azure Sphere can ensure the consistency of coffee recipes and taste around the world, reduce resource waste, energy consumption, and predict equipment operation and maintenance."

Reference address:Unveiling IoT security solutions: Microsoft Azure Sphere

Previous article:Akamai: 20% of credential stuffing attacks target media companies
Next article:ON Semiconductor Offers Veridify Public Key Security Tools

Recommended ReadingLatest update time:2024-11-16 15:20

Suspected Microsoft lightweight operating system exposed: named Windows 11 SE
Microsoft has put a lot of effort into developing a more lightweight operating system to potentially compete with ChromeOS. Microsoft has scheduled an event for June 24, promising to unveil the next generation of Windows. However, recently the internet has been flooded with leaked screenshots, wallpapers, and more o
[Mobile phone portable]
Suspected Microsoft lightweight operating system exposed: named Windows 11 SE
Microsoft Hardware from the 1980s You May Not Know: IBM PC Performance Expansion Card
Maybe you still don’t know that Microsoft had hardware products at the beginning of its development. In 1982, Microsoft released RAM cards for IBM PCs. According to the veteran magazine "PC Magazine", it not only allows users to expand the available memory of IBM personal computers from 64K to 256K, but also allows us
[Home Electronics]
Microsoft Hardware from the 1980s You May Not Know: IBM PC Performance Expansion Card
Microsoft's Xbox Series S Easter egg: Master Chief portrait on the power supply
      Windows Phones never really got attention inside Microsoft,media windowslatest reported.The software giant couldn't make up for the product's application gap and a host of other management mistakes, which led to a complete mess.When Microsoft stopped providing new features for Windows 10 Mobile, the idea of ​​in
[Mobile phone portable]
Microsoft is also going to stop using Windows 10 Mobile
    Microsoft Windows 10 Mobile ended service on December 10, 2019, when Microsoft also released the last cumulative update. However, according to foreign media reports, Windows 10 Mobile users can still have an extra month of use.   Microsoft wrote on the page for the KB4522812 update for Windows 10 Mobile (OS Buil
[Mobile phone portable]
Microsoft is also going to stop using Windows 10 Mobile
CrowdStrike update triggers Windows blue screen crisis, Microsoft reveals the root cause
July 29 news, over the past ten days, CrowdStrike and Microsoft have been working hard to assist users affected by the massive Windows blue screen of death problem. The problem was caused by a faulty update of CrowdStrike. In addition to providing a solution, CrowdStrike has released a preliminary post-incident revi
[Embedded]
Intel and Microsoft pledge to continue supporting Huawei
According to PCWorld, a Microsoft spokesperson said in a statement that it will continue to provide Microsoft software updates to customers of Huawei devices. With the US government imposing a ban on Huawei, the biggest question consumers may be facing is whether Huawei's Matebook laptops are safe to buy, or whether
[Internet of Things]
Intel and Microsoft pledge to continue supporting Huawei
Azure ARM (19) Migrate traditional ASM VM to ARM VM (2)
  As we have mentioned in the previous section:  Azure ARM (18) Migrating traditional ASM VMs to ARM VMs (1)   Azure Virtual Network has been created. After migrating the Virtual Network, we can migrate all VMs (LeiVM01 and LeiVM02) in the VNet to ARM mode.      The official migration is divided into two parts:   1.
[Microcontroller]
Azure ARM (19) Migrate traditional ASM VM to ARM VM (2)
Hackers claim to have stolen 37GB of Microsoft source code, including Bing and Cortana
On the morning of March 23, a hacker group claimed to have obtained about 37GB of Microsoft source code, which is related to hundreds of projects including Bing search and Cortana voice assistant. This is the latest in a series of major cyber crimes. Released by the hacker group "Lapsus$" on Monday night,
[Mobile phone portable]
Hackers claim to have stolen 37GB of Microsoft source code, including Bing and Cortana
Latest Internet of Things Articles
Change More Related Popular Components

EEWorld
subscription
account

EEWorld
service
account

Automotive
development
circle

About Us Customer Service Contact Information Datasheet Sitemap LatestNews


Room 1530, 15th Floor, Building B, No.18 Zhongguancun Street, Haidian District, Beijing, Postal Code: 100190 China Telephone: 008610 8235 0740

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号