8 ms·
I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and c
by darzu 6y ago
I worked extensively with Pluton when I was employed on Azure Sphere (an IoT platform marketed as highly secure and composed of a linux-based OS, ARM SoC, and cloud service). I might be able to answer questions about this.
Here’s a blog by the engineer lead on Azure Sphere that discusses Pluton:
https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-mcu/ https://azure.microsoft.com/en-us/blog/anatomy-of-a-secured-...
Disclaimer: I still work at MSFT but in a different org.
- yellowapple 6y agoThe pressing concern for me: what does this mean for non-Windows operating systems running on Pluton-equipped systems? Will there be a possibility for non-Windows software to use Pluton's features?
- darzu 6y agoI can only comment on the technical details I know of, not the business objectives of the parties involved. From a technical standpoint, Azure Sphere's OS was built on Linux. As far as I know, there isn't anything Windows specific to Pluton. Pluton was a separate (heavily-modified) ARM M4 core which we interfaced with from the main A7 core via a secure mailbox channel, which was again OS agnostic.
- rektide 6y agoFrustrating that the announcement was made with so little technical details easily findable. This kind of decision- to use an ARM core- seem pretty questionable. That's how things always were done, but it feels like another UEFI/FAT32 situation, dragging in old encumbering legacy baggage with big IP implications, when there are available other options (RISC-V). It feels like this decision is being made literally one year too soon. Fixing the old, archaic in to place.
- gmueckl 6y agoIf this is intended to be a secure enclave, then it need to be pretty much a black box with a mininal interface to the outside world. Changing what is inside the box should be possible at any time then. On the other hand, why does it even matter that you know the CPU instruction set that's used inside the box when you can't ever have direct access to it?
- 29athrowaway 6y agoIt means that once most CPUs have the chip, they'll execute order 66 and other OSes will be blocked.
- cm2187 6y agoA TPM integrated into the CPU makes sense (and I am puzzled why TPMs aren't a standard feature of all MB given the modest cost). But what about that diagram in the article with a link to the cloud? Will this thing phone home outside of the control of the OS?
- darzu 6y agoIn Azure Sphere, Pluton didn't do any direct network communication, that was all handled by the main core. Also there was no cellular so the whole system depended on user interaction to get online. When the main core wanted to talk to the Azure Sphere cloud service (from Linux user land), it would go through a remote attestation process that involved Pluton. Pluton can securely track what software was booted on the main core (called "measure boot") and it basically sends a hash of that to the cloud to prove to the cloud what software is currently running. So I imagine the chip-to-cloud thing they're talking about is this remote attestation protocol. Also, it's possible the term "Pluton" has been expanded to refer to more than just the M4 chip we used in Azure Sphere.
- josh2600 6y agoI guess I’m wondering how Pluton and SGX coexist...
- xenocratus 6y agoFrom what I understand, Pluton is more in the vein of TPMs, so able to store and handle your cryptographic keys and to do measurements during your boot process. SGX is a hardware feature that allows an app to run securely (i.e. Without any possible interference from other apps or even the OS) in a hardware-enforced enclave. Completely different tasks and use cases, which might overlap - maybe you can use keys with Pluton from within an SGX enclave?
- Mindwipe 6y agoI think you should assume Pluton will be used instead of SGX, which is so broken nobody has any confidence in it any more.
- Asmod4n 6y agoSo.. this basically means swapping your CPU gets rid of anything you stored on its "TPM", or can it be backuped up to the TPM of your Mainboard and restored to the new one you install?
- darzu 6y agoI think the whole idea here is that Pluton will be integrated inside of the same physical chip as the CPU. So physically swapping CPUs would swap your Pluton core too. But the Pluton I know of didn't really have any writeable storage. It had some special ROM and fuses that it uses internally for its private keys but that's basically it.
- gmueckl 6y agoDid all units share the same set of keys? Isn't that an attack vector?
- chem83 6y agoGreetings! - Was Pluton based on an RTOS or is it running on bare-metal on top of the M4? - Is the architecture on the i.MX8-based Sphere the same as the one on MT3620? - Does the Security Subsystem running on the Cortex-A's secure world have any relationship with Pluton? Is the Security Subsystem running on top of the Sphere's modified Linux kernel like the normal world is? Thanks, cheers!
- darzu 6y ago1. Bare-metal 2. I only worked with the MT3620 so I cannot comment on others 3. Pluton would boot the A7’s Secure World which would the boot A7 normal world. Secure World and Pluton interfaced regularly but they’re fundamentally different code and purposes. Hope that helps!
- carlsborg 6y ago1. Is this specific to Azure Sphere CPUs? Or are general purpose intel CPUs going to have this capability. 2. If the latter, "Every piece of software on an Azure Sphere device must be signed by Microsoft." what does the OS interface look like?
- darzu 6y ago1. I assume this is not just for Azure Sphere since the goal when I was there was to be a low-cost, low-energy platform. Also the announcements make it sound like a general offering. 2. Pluton can check the signature of software before booting it on the A7 core. Hope that helps!
- deleted 6y ago[deleted]
- michaelt 6y agoWill this be virtualisable so multiple VMs sharing a host will see separate, independent devices? On desktops and laptops, will this device have a hardwired user-presence sensor, like Yubikeys do? Would this device be performance-oriented enough to, for example, terminate SSL? I gather TPMs can, but only unhelpfully slowly [1] Would it be performance-oriented enough to perform disk encryption? What about memory encryption? [1] https://blog.habets.se/2012/02/Benchmarking-TPM-backend-SSL.html https://blog.habets.se/2012/02/Benchmarking-TPM-backend-SSL....
- darzu 6y agoI’m pretty sure Azure Sphere used Pluton to do encryption for SSL. I don’t have any numbers, but one of the goals of Pluton was to accelerate crypto operations. But this was for a microcontroller context so I’m not sure about desktop/laptop class performance. I don’t think pluton was used for disk or memory encryption, in Azure Sphere but I believe the possibility was discussed. I’m afraid I don’t have anything more than speculation for the rest.
- deleted 6y ago[deleted]
- hanselot 6y agoExcuse me for asking, but what possible reason could I have to trust MS INSIDE my CPU?
- 29athrowaway 6y agoCan you explain why an end-user would need this in practice?