Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other...

32
Azure Sphere Giovanni Gatto Solution Specialist

Transcript of Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other...

Page 1: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Azure Sphere

Giovanni Gatto

Solution Specialist

Page 2: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

9 BILLION new MCU devices

built and deployed every year

Microcontrollers

(MCUs) low-cost, single

chip computers

Page 3: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Fewer than 1% of MCUs are connected today.

Page 4: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.
Page 5: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Opportunity Risk

Page 6: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

What happens when you connect

a device to the internet?

“The internet is this caldron of evil.” Dr. James Mickens, Harvard University

Page 7: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

“When smart gadgets spy on you: Your home life is less private than you think”

“Protecting Your Family: The Internet of Things Gives Hackers Creepy New Options”

Page 8: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Everyday devices are used to

launch an attack that takes

down the internet for a day

100k devices

Exploited a well known weakness

No early detection, no remote update

Mirai Botnet attack

Page 9: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Attackers gain access to casino

database through fish tank

Entry point was a connected thermometer

Once in, other vulnerabilities were exploited

Gained access to high-roller database

Hackers attack casino

Page 10: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

No manufacturer wants to make insecure devices

Terrorists Ignite Thousands of House Fires with Hacked Stoves

From: HackersTo: ConsumerSubject: Your Fridge

We control your fridge.Send us $5 in bitcoin or else…

Page 11: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

How will you respond when your devices are

compromised or under attack?

I don’t feel like this question is perfect – couldn’t remember exactly what we said in the hallway…

You’ll try to keep the hackers out of your device.

But, what will you do if they get in?

Page 12: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

The internet security battle.

We’ve been fighting it for decades. We have experience to share.

Page 13: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Security is foundational

It must be built in from the beginning.

Page 14: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Hardware

Root of Trust

Defense

in Depth

Small Trusted

Computing Base

Dynamic

Compartments

Certificate-Based

Authentication

Failure

Reporting

Renewable

Security

The 7 properties of highly secured devices

https://aka.ms/7properties

Page 15: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

© Microsoft Corporation

Some properties depend only on hardware support

Unforgeable cryptographic keys

generated and protected by hardware

Hardware Root of Trust

• Hardware to protect Device Identity

• Hardware to Secure Boot

• Hardware to attest System Integrity

Hardware

Root of Trust

Page 16: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

© Microsoft Corporation

Internal barriers limit the reach of any

single failure

Dynamic Compartments

• Hardware to Create Barriers

• Software to Create Compartments

Some properties depend on hardware and software Dynamic

Compartments

Defense in

DepthSmall Trusted

Computing Base

Page 17: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

© Microsoft Corporation

Device security renewed to overcome

evolving threats

Renewable Security

• Cloud to Provide Updates

• Software to Apply Updates

• Hardware to Prevent Rollbacks

Some properties depend on hardware, software and cloud

Certificate-Based

Authentication

Failure

Reporting

Renewable

Security

Page 18: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Meeting these seven properties is difficult and costly

Design and build

a holistic solution

Recognize and mitigate

emerging threats

Distribute and apply

updates on a global scale

Page 19: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Azure Sphere

Certified MCUs

The Azure Sphere

Operating System

The Azure Sphere

Security Service

Azure Sphere is an end-to-end solution for securing MCU powered devices

Page 20: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Azure Sphere Certified MCUs from silicon partners, with built-in Microsoft

security technology provide connectivity and

a dependable hardware root of trust.

Page 21: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

© Microsoft Corporation

Connected with built-in networking

Secured with built-in Microsoft silicon security

technology including the Pluton Security Subsystem

Crossover real-time and application processing

power brought to MCUs for the first time

Azure Sphere certified MCUs create a secured root of trust for connected, intelligent edge devices

ARM Cortex-MFor real-time processing

ARM Cortex-AOptimized for

low power

SRAM≥ 4MB

Network ConnectionWi-Fi in first chips

Microsoft

PlutonSecurity

Subsystem

Multiplexed I/O

SPII2CUARTI2STDMPWMGPIO ADC

FLASH ≥ 4MB

Firewall Firewall Firewall

Firewall Firewall Firewall

Page 22: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.
Page 23: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

The Azure Sphere Operating Systema four-layer defense in depth OS with ongoing updates

creates a secured platform for IoT experiences.

Page 24: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.
Page 25: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

The Azure Sphere Security Service guards every Azure Sphere device; it brokers trust for

device-to-device and device-to-cloud communication,

detects emerging threats, and renews device security.

Page 26: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Azure Sphere is open

Open to any MCU manufacturerWe are licensing our Pluton security subsystem

royalty free for use in any chip

Open to any innovationMCU manufacturers are free to innovate with our

GPL’d OSS Linux kernel code base

Open to any cloudAzure Sphere devices are free to connect to

Azure or any other cloud, proprietary or public

for application data

Azure Sphere is Open.

Page 27: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Three components. One low price. No subscription fees.

An Azure Sphere certified MCU

The Azure Sphere OS

with ongoing on-device OS updates

The Azure Sphere Security Service

with ongoing on-device security updates

Page 28: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Simplify development

Focus your device development

effort on the value you want

to create

Streamline debugging

Experience interactive, context-

aware debugging across device

and cloud

Collaborate across your team

Apply tool-assisted collaboration

across your entire development

organization

Microsoft has modernized MCU development with Azure Sphere, Visual Studio, and Azure DevOps

Page 29: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Faster time to market

PRODUCTIVITY

The future is now

OPPORTUNITY

Peace of mind

SECURITY

Page 30: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Get Started with Azure Sphere Today!

Try today: http://www.azure-sphere.com

Now available▪ Azure Sphere development kits from Seeed studios

Public preview availability ▪ Azure Sphere OS

▪ Azure Sphere Security Service

▪ Visual Studio tools for Azure Sphere

Page 31: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

Opportunity RiskResponsibility

Page 32: Azure Sphere - Microsoft€¦ · Azure Sphere devices are free to connect to Azure or any other cloud, proprietary or public for application data Azure Sphere is Open. Three components.

© 2018 Microsoft Corporation. All rights reserved.

Thank you!