The Arrow Security Starter Kit Portfolio
The Arrow Security Starter Kit portfolio has variants that support two wireless end node configurations and two gateway/edge compute solutions. These kits incorporate the Infineon OPTIGA™ TPM 2.0 and OPTIGA™ Trust M technologies and function independently or in combination to provide a secure end-to-end solution. Created with FreeRTOS or Linux, the portfolio supports AWS IoT Greengrass, and/or AWS IoT Core right out-of-the-box.
Gateways/Edge Compute Solution with Infineon OPTIGA™ Trusted Platform Module (TPM) 2.0
These kits use OPTIGA™ TPM 2.0 with AWS services to develop a gateway or edge compute solution enabled with a hardware layer security. They include a Tresor Mezzanine board with the OPTIGA™ TPM 2.0, and the Arrow 96Boards SBCs based on ST Micro STM32MP1 or NXP i.MX 8X processors.
Wireless End Node Security Kits with OPTIGA™ Trust M
These boards support Bluetooth LE and LTE-M connectivity. Trust M S2GO, which includes the OPTIGA™ Trust M, connects to the ST STM32WB55 EVK or the Silicon Labs Giant Gecko board. Arrow provides Android & iOS based mobile applications, which function as the BLE to WiFi conversion for AWS cloud services connectivity.
Security Feature Implemented | Description |
Unique Device Identifier | EUI64 is used and stored in the OPTIGA™ embedded security solution |
Secure Boot | Software based secure boot feature performed with OPTIGA™ embedded security solution |
Secure OTA Updates | Implemented software-based capability for OTA updates with OPTIGA™ embedded security solution |
Secure Data (encryption) | Data encrypted and decrypted using keys stored in the OPTIGA™ embedded security solution |
Device Authentication | Device authentication enabled in the OPTIGA™ embedded security solution |
Device Management (Allow/Deny) | Performed in AWS Cloud Services |
Isolation of secure firmware from non-secure application | Stored in the OPTIGA™ embedded security solution |
Isolation of credentials (keys) in a Tamper-& resistant element | Stored in the OPTIGA™ embedded security solution |
X.509 certificate support | A digital certificate to verify that a public key belongs to the Hostname/domain or organization and stored in the OPTIGA™ embedded security solution |
Secure Supply Chain | Register Root CA in AWS and using Root CA to create the device certificate. An Intermediate CA is not employed. Private key and device certificate are stored in the OPTIGA™ embedded security solution |
Gateway/Edge Compute Solutions:
See related product
See related product
Wireless End Node Solutions:
See related product
See related product