Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-...
Disclaimer: I still work at MSFT but in a different org.
Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton: https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-...
Disclaimer: I still work at MSFT but in a different org.
From a technical standpoint, Azure Sphere's OS was built on Linux. As far as I know, there isn't anything Windows specific to Pluton. Pluton was a separate (heavily-modified) ARM M4 core which we interfaced with from the main A7 core via a secure mailbox channel, which was again OS agnostic.
This kind of decision- to use an ARM core- seem pretty questionable. That's how things always were done, but it feels like another UEFI/FAT32 situation, dragging in old encumbering legacy baggage with big IP implications, when there are available other options (RISC-V).
It feels like this decision is being made literally one year too soon. Fixing the old, archaic in to place.
When the main core wanted to talk to the Azure Sphere cloud service (from Linux user land), it would go through a remote attestation process that involved Pluton. Pluton can securely track what software was booted on the main core (called "measure boot") and it basically sends a hash of that to the cloud to prove to the cloud what software is currently running.
So I imagine the chip-to-cloud thing they're talking about is this remote attestation protocol.
Also, it's possible the term "Pluton" has been expanded to refer to more than just the M4 chip we used in Azure Sphere.
oh dear
- Was Pluton based on an RTOS or is it running on bare-metal on top of the M4? - Is the architecture on the i.MX8-based Sphere the same as the one on MT3620? - Does the Security Subsystem running on the Cortex-A's secure world have any relationship with Pluton? Is the Security Subsystem running on top of the Sphere's modified Linux kernel like the normal world is?
Thanks, cheers!
Hope that helps!
On desktops and laptops, will this device have a hardwired user-presence sensor, like Yubikeys do?
Would this device be performance-oriented enough to, for example, terminate SSL? I gather TPMs can, but only unhelpfully slowly [1]
Would it be performance-oriented enough to perform disk encryption? What about memory encryption?
[1] https://blog.habets.se/2012/02/Benchmarking-TPM-backend-SSL....
I don’t think pluton was used for disk or memory encryption, in Azure Sphere but I believe the possibility was discussed.
I’m afraid I don’t have anything more than speculation for the rest.
2. If the latter, "Every piece of software on an Azure Sphere device must be signed by Microsoft." what does the OS interface look like?
2. Pluton can check the signature of software before booting it on the A7 core.
Hope that helps!
But the Pluton I know of didn't really have any writeable storage. It had some special ROM and fuses that it uses internally for its private keys but that's basically it.