Advanced hardware security for IoT at scale
The Shield96 board based on Microchip silicon is available in two different forms.
The Shield96 Standard reference platform provides a secure solution applicable across all IoT verticals. This trusted Linux turn-key solution addresses hardware security by design. This hardware allows users the ability to design a solution as needed to fit their custom needs.
The Shield96 Trusted Platform comes preloaded with the EmSPARK Security Suite software by Sequitur Labs. This provides a secure platform applicable across all IoT verticals to enable secure end point solutions and protect firmware, keys and data throughout the lifecycle of a product. EmSPARK is the essential software companion suite complementing the Microchip hardware providing a cost-effective secure solution appropriate for every connected device built with the ATSAMA5D2 processor. Engineers can leverage this reference design for digital transformation built on trust extracting the full value of the advanced embedded security features of the ATSAMA5D2.
Security features
- Secure firmware update
- Secure storage
- Tamper detection
- Managed key store and certified authority store
- Unique device ID, immutable, bound to the hardware root of trust (HWRoT)
- Crypto engine in secure domain with OpenSSL adaptor
- (Trusted Platform version only) Preloaded with EmSPARK from Sequitur Labs
Hardened security simplified
- Pre-configured to use ATSAMA5D2 security architecture
- Secure boot
- Strong domain partitioning
- On-the-fly memory encryption/decryption
- Hardware crypto engines
- Simple abstraction APIs for the hardware security features and preloaded keys and certificates
- Hardware enforced domain isolation (Arm® TrustZone®) for security related tasks, keystore and certificate management
- Secure provisioning provides firmware packaging for manufacturing and secure provisioning in non-secure facilities
Advanced security capabilities. Delivered. (Trusted_Platform)
- Trusted boot – Integrity and confidentiality assurance from the entire boot chain from bootloader to TEE to Linux kernel
- Firmware Protection – Encryption of embedded firmware and execution of authenticated firmware
- Trusted Device ID – Unique device certificate securely constructed through provisioning, protected by TrustZone
- Secure storage – Encrypted storage for application data and key material
- Secure communications – Strong security for TLS/SSL stack and mutual authentication
- Secure firmware updates – Predefined firmware update function complementing the trusted boot architecture
Arrow Secure Programming and Provisioning Technology
Arrow‘s Secure Programming and Provisioning Technology is based on a highly secure and reliable chain of trust. Arrow Electronics has the infrastructure, technology and knowledge to enable customers of all sales and demand profiles to take full advantage of silicon based security features. Provisioning of secure elements and crypto hardware enables precise identification and authentication of devices as well as excellent anti-counterfeiting and brand protection.