Wpisy

IoT Security with latest SLM 9670 Industrial Grade TPM 2.0

Like other embedded systems, Industrial IoT design faces a constant stream of threats. As hackers adopt new attacks, developers rush to close security holes. Deployed devices need to update IoT firmware, increasing potential security vulnerabilities. For example, using a simple firmware verification check can leave the software published. In this situation, the developer may expect to be able to query external resources for verification and catch attempts to replace the firmware with hacked code. However, even relatively novice hackers can replace the firmware with code that ignores such verification checks. To secure these vurnerabilities comes Industrial Grade TPM 2.0.

Securing devices with Infineon industrial grade TPM

Infineon Technologies AG has unveiled a new security chip that defines the first TPM (Trusted Platform Module), designed specifically for industrial applications such as industrial computers, servers, industrial controllers and edge gates. The module protects confidential data in connected devices and reduces the risk of leakage of this information due to attacks, e.g. hackers.

The OPTIGA TPM SLM 9670 module protects the integrity of industrial systems and the identity of users using them. The system controls access to sensitive data at key locations in industrial environments, such as an automated factory. It also protects the cloud interface if the network uses one. The security system fully meets the TPM 2.0 standard developed by the Trusted Computing Group and is certified by an independent test laboratory in accordance with the criteria contained in this standard. The new module is meticulously controlled and certified by Infineon. Thanks to its use, it is possible to shorten the time of designing and introducing the device to the market, thanks to the ready security solution in the system.

The TPM system has a lifetime declared as 20 years. It allows programmers to perform firmware updates, which in turn enables them to meet the long-term security requirements in rapidly changing industrial environments. In this way, it can also reduce maintenance costs of industrial equipment thanks to secured remote software updates. The TPM chip will be available in serial production in the second half of 2019.

TPM 2.0 Key Features

  • Random Number Generator (RNG) according to NIST SP800-90A
  • TPM FW update functionality installed
  • 6962 Bytes of free NV memory
  • Full personalization with Endorsement Key (EK) and EK certificate
  • Up to 3 keys in the volatile memory
  • Up to 7 keys in the NV memory
  • Up to 8 NV counters
  • Support of various cryptographic algorithms:
    • RSA-1024 and RSA-2048
    • SHA-1 and SHA-256
    • ECC NIST P256
    • ECC BN256

Security chip implementation in Industrial IoT devices

With knowledge of latest Industrial IoT security measures, the choice of proper end-point conroller or gateway is much easier than you think. Some manufacturers can implement TPM 2.0 security chip in production process, to allow users to generate certification keys after purchase, maximizing security of their installations. TECHBASE offers wide range of solutions, optionally aided with TPM system.

For example, ESP-32 based solution, Moduino X series and eModGATE series products offer the support for such security measures. Read more in Industrial IoT Ecosystem brochure, to understand the importance of reliable and secure hardware for Industrial IoT.

ESP32-WROVER-B

Upgraded Espressif’s ESP32 module platform for Moduino X

Espressif, a manufacturer of popular ESP32-based IoT solutions, has developed a new version of the ESP32-WROVER module, called ESP32-WROVER-B. Updated module, in addition to the dual-core LX6 microprocessor, has now twice the amount of RAM, compared to previous version of the WROVER module. The ESP32 module can work with Pseudo Static RAM. Up to now, modules with up to 4MB RAM have been the most common. Recently Espressif Systems introduced a new ESP32-WROVER-B module, which is equipped with up to 8MB pSRAM.

ESP32-WROVER-B

The new module is compatible with TECHBASE’s Moduino X series of IIoT devices. The system works with MicoPython, ESP-IDF (freemask based on FreeRTOS with light-weight Internet Protocol), Mongoose OS, Zephyr Project and is Arduino compatible. ESP32-WROVER-B is based on the ESP32-D0WD system with dimensions 5 x 5 mm, which replaced the earlier ESP32-D0WDQ6 (6 x 6 mm). The ESP32-D0WD model has 2 CPU cores that can be controlled independently. The CPU clock frequency can also be configured in the range of 80 to 240 MHz.

Updated Moduino X with ESP32-WROVER-B also comes with variety of Flash Memory available: 4MB and 16MB.

To read more about Industrial Moduino X solution, visit: https://moduino.techbase.eu/

To order sample devices, loor for  ESP32-WROVER-B option in Moduino X product configurator module:

New base platforms for Moduino device

Revised version of TECHBASE’s Moduino edge controller offers now support and compatibility with wide range of Pycom’s compute modules with built-in communication interfaces, e.g. LoRa, Sigfox, NarrowBand-IoT / LTE cat. M1/NB1 and WiFi/BT4.2, similarly to standard Moduino devices, powered by Espressif’s ESP32-WROVER module.

With new Moduino platform you can choose from variety of Pycom modules to power the unit, in order to receive specific wireless features. At the present day Moduino supports these models:

    • WiPy 3.0 with WiFi & Bluetooth 4.2
    • SiPy with WiFi/BT and Sigfox
    • LoPy4 with WiFi/BT and LoRa, Sigfox
    • GPy with WIFi/BT and NarrowBand-IoT / LTE cat.M1/NB1
    • FiPy with WIFi/BT and LoRa, Sigfox, NarrowBand-IoT / LTE cat.M1/NB1

If physical network connection is a must, you can always choose standard Moduino ESP32 with Ethernet expansion module to ensure communication via LAN. Of course the possibility to choose wired-to-wireless communication is also available with the Moduino configurator.

All Pycom-based Moduino solutions are compatible with wide range of interface expansions for standard Moduino ESP32 platform, e.g. RS-232/485, Analog I/Os, Digital I/Os, Relay, CAN and many more, including SuperCap & OLED screen options. You can find the whole list of available expansions here: https://iiot-shop.com/product/moduino/

To read more about Industrial Moduino X solution, visit: https://moduino.techbase.eu/

 

ESP32-WROVER-B

Upgraded Espressif’s ESP32 module platform for Moduino X

Espressif, a manufacturer of popular ESP32-based IoT solutions, has developed a new version of the ESP32-WROVER module, called ESP32-WROVER-B. Updated module, in addition to the dual-core LX6 microprocessor, has now twice the amount of RAM, compared to previous version of the WROVER module. The ESP32 module can work with Pseudo Static RAM. Up to now, modules with up to 4MB RAM have been the most common. Recently Espressif Systems introduced a new ESP32-WROVER-B module, which is equipped with up to 8MB SPI PSRAM.

ESP32-WROVER-B

The new module is compatible with TECHBASE’s Moduino X series of IIoT devices. The system works with MicoPython, ESP-IDF (freemask based on FreeRTOS with light-weight Internet Protocol), Mongoose OS, Zephyr Project and is Arduino compatible. ESP32-WROVER-B is based on the ESP32-D0WD system with dimensions 5 x 5 mm, which replaced the earlier ESP32-D0WDQ6 (6 x 6 mm). The ESP32-D0WD model has 2 CPU cores that can be controlled independently. The CPU clock frequency can also be configured in the range of 80 to 240 MHz.

Updated Moduino X with ESP32-WROVER-B also comes with variety of Flash Memory available: 4MB, 8MB and 16MB.

To read more about Industrial Moduino X solution, visit: https://moduino.techbase.eu/

To order sample devices, visit our new Industrial IoT Shop and ask our Sales Department via chat about new Moduino X with ESP32-WROVER-B module: