Azure Sphere
Azure Sphere is a secured, high-level application platform with built-in communication and security features for internet-connected devices. The platform consists of the integration of hardware built around a secured silicon chip; the Azure Sphere OS, a custom high-level Linux-based operating system; and the Azure Sphere Security Service, a cloud-based security service that provides continuous, renewable security. Azure Sphere security was designed based on Microsoft Research's position on the seven properties required of highly secure devices.
Azure Sphere OS
The Azure Sphere OS is a custom Linux-based microcontroller operating system created by Microsoft to run on an Azure Sphere-certified chip and to connect to the Azure Sphere Security Service. The Azure Sphere OS provides a platform for Internet of Things application development, including both high-level applications and real-time capable applications. It is the first operating system running a Linux kernel that Microsoft has publicly released and the second Unix-like operating system that the company has developed for external users, the other being Xenix.Azure Sphere Security Service
The Azure Sphere Security Service, sometimes referred to as AS3, is a cloud-based service that enables maintenance, updates, and control for Azure Sphere-certified chips. The Azure Sphere Security Service establishes a secure connection between a device and the internet and/or cloud services and ensures secure boot. The primary purpose of contact between an Azure Sphere device and the Azure Sphere Security Service is to authenticate the device identity, ensure the integrity and trust of the system software, and to certify that the device is running a trusted code base. The service also provides the secure channel used by Microsoft to automatically download and install Azure Sphere OS updates and customer application updates to deployed devices.Azure Sphere chips and hardware
Azure Sphere-certified chips and hardware support two general implementation categories: greenfield and brownfield. Greenfield implementation involves designing and building new IoT devices with an Azure Sphere-certified chip. Azure Sphere-certified chips are currently produced by MediaTek. In June 2019, NXP announced plans to produce a line of Azure Sphere-certified chips. In October 2019, Qualcomm announced plans to produce the first Azure Sphere-certified chips with cellular capabilities. Brownfield implementation involves the use of an Azure Sphere guardian device to securely connect an existing device to the internet. Azure Sphere guardian modules are currently produced by Avnet.MediaTek 3620
MT3620 is the first Azure Sphere-certified chip and includes an ARM Cortex-A7 processor, two ARM Cortex-M4F I/O subsystems, 5x UART/I2C/SPI, 2x I2S, 8x ADC, up to 12 PWM counters and up to 72x GPIO, and Wi-Fi capability. MT3620 contains the Microsoft Pluton security subsystem with a dedicated Arm Cortext-M4F core that handles secure boot and secure system operation.Azure Sphere Hardware
Azure Sphere-certified chips can be purchased in several different hardware configurations produced by Microsoft partners.Modules
- Avnet Wi-Fi Module
- AI-Link Wi-Fi Module
- USI Dual Band Wi-Fi Module
- Avnet MT3620 Starter Kit
- Seeed MT3620 Dev Board
- Seeed MT3620 Mini Dev Board
- Avnet Guardian Module
Azure Sphere Guardian module
Microsoft Pluton
Pluton is a Microsoft-designed security subsystem that implements a hardware-based root of trust for Azure Sphere. It includes a security processor core, cryptographic engines, a hardware random number generator, public/private key generation, asymmetric and symmetric encryption, support for elliptic curve digital signature algorithm verification for secured boot, and measured boot in silicon to support remote attestation with a cloud service, and various tampering counter-measures.Application development
The Linux-based Azure Sphere OS provides a platform for developers to write applications that use peripherals on the Azure Sphere chip. Applications can run on either the A7 core with access to external communications or as real-time capable apps on one of the M4 processors. Real-time capable applications can run on either bare metal or with a real-time operating system. Developer applications can be distributed to Azure Sphere devices through the same secure mechanism as the Azure Sphere OS updates.Timeline
The following is a list of announcements and releases from Microsoft around Azure Sphere.Date | Description |
2018-05-21 | Azure Sphere Announcement |
2018-09-24 | Azure Sphere services are in public preview and dev kits are broadly available |
2018-10-22 | Explanation of Azure Sphere tenant concept |
2018-11-05 | Upcoming Azure Sphere 18.11 release |
2018-11-16 | Update 18.11 for Azure Sphere in public preview |
2019-01-07 | Description of Azure Sphere secured MCU |
2019-01-09 | Azure Sphere: Update to the 18.11 release |
2019-02-15 | Azure Sphere 19.02 Release |
2019-03-15 | Update 19.03 for Azure Sphere public preview now available for evaluation |
2019-03-29 | Update 19.03 for Azure Sphere public preview now available in Retail feed |
2019-04-10 | Update 19.04 for Azure Sphere public preview now available for evaluation |
2019-04-24 | Update 19.04 for Azure Sphere public preview now available in Retail feed |
2019-05-16 | Update 19.05 for Azure Sphere public preview now available for evaluation |
2019-05-31 | Azure Sphere 19.05 Release Unlocks new features in the MT3620 |
2019-06-24 | Update 19.06 for Azure Sphere public preview now available for evaluation |
2019-07-08 | Update 19.06 for Azure Sphere public preview now available in Retail feed |
2019-07-17 | Update 19.07 for Azure Sphere public preview now available for evaluation |
2019-07-31 | The latest update to Azure Sphere is now available in the retail feed |
2019-09-25 | Azure Sphere Preview—Update 19.09 is now available for evaluation |
2019-11-01 | Microsoft announces Azure Sphere will be generally available in February 2020 |
2019-11-07 | Update 19.10 for Azure Sphere now available |
2019-12-06 | Azure Sphere update 19.11 is now available via retail feed |
2020-02-24 | Azure Sphere is now Generally Available |