Product Brief Security Starter Kit with STM32WB55 and OPTIGA™ Trust M Arrow has worked closely with several technology suppliers to create a solution that employ’s ten major security features and take the guesswork out of implementation and reducing your overall time to market. The Arrow Security Starter Kit integrates the FreeRTOS open-source software framework, with readily available BLE based evaluation kit from ST Micro, Infineon’s OPTIGA™ Trust M secure solution and AWS IoT Core. AWS IoT Core is a service that enables you to connect devices to AWS, while providing secure data, interactions, process and act upon the device data. Using this kit, device makers can easily add security to their end products while adhering to the latest security standards, including ETSI TS 103 645, NISTIR 8259A, and ISO 27001. Security Starter Kit with ST Micro STM32WB55 and OPTIGA™ Trust M This combination includes a Trust M S2GO board (Shield2Go) and the ST Micro P-Nucleo-WB55 EVK. The STM32WB55 EVK supports BLE and Bluetooth® 5 connectivity. The Trust M S2GO Board has one OPTIGA™ Trust M security chip on an easy-to-handle PCB. It provides a root of trust in the form of a unique X.509 certificate coupled with hardware support to establish a MQTT and TLS (Transport Layer Security) connection between devices and cloud, forming a robust basis for secured communication. Arrow also provides iOS and Android mobile apps, which are used for provisioning, authentication and communication between the Security Starter Kit and the Cloud. Part Number: STM32WB55-SSK Security Feature Implemented Description Unique Device Identifier EUI64 is used and stored in the OPTIGATM Trust M Secure Boot Software based secure boot feature performed with OPTIGATM Trust M Secure OTA Updates Implemented software-based capability for OTA updates with OPTIGATM Trust M Secure Data (encryption) Data encrypted and decrypted using keys stored in the OPTIGATM Trust M Device Authentication Device authentication feature enabled in the OPTIGATM Trust M Device Management (Allow/Deny) Performed in AWS Cloud Services Isolation of secure firmware from non-secure application Stored in the OPTIGATM Trust M Isolation of credentials (keys) in a Tamper-resistant element Stored in the OPTIGATM Trust M X.509 certificate support A digital certificate to verify that a public key belongs to the Hostname/domain or organization and stored in the OPTIGATM Trust M Secure Supply Chain Register Root CA in AWS and using Root CA to create the device certificate. An Intermediate CA is not employed. Private key and device certificate are stored in the OPTIGATM Trust M Security Starter Kit with STM32WB55 and OPTIGA™ Trust M Out-of-the-Box Demonstration with Infineon OPTIGA™ Trust M for Wireless End Nodes The demo integrates FreeRTOS in a BLE configuration with the OPTIGA™ Trust M on the ST Micro STM32WB55 EVK . AWS IoT Core is also enabled and securely communicates with the Cloud. STM32WB55-SSK Kit Contents: • • • • • • STM32WB55 EVK (P-NUCLEO-WB55) Infineon S2GO Security OPTIGA™ Trust M EVK Custom cable connecting OPTIGA™ Trust M with STM32WB55 P-Nucleo board Micro USB cable (power and communication from PC) User & Developer Guides, iOS & Android mobile applications and Cloud Connect Tool installation guide available on: https://www.arrow.com/en/products/stm32wb55-ssk/arrow-development-tools Cloud Connect tool & FreeRTOS source code includes example code, application and demo provided on Github. https://github.com/ArrowElectronics/Security-Starter-Kits Wireless End Node Solution ST Micro Infineon S2GO P-Nucleo-WB55 EVK Security OPTIGA™ Trust M Tablet or Mobile device not included Cloud Connect Tool About Arrow Engineering Services with eInfochips eInfochips, an Arrow company, is a leading global provider of product engineering and semiconductor design services. With over 500+ products developed and 40M deployments in 140 countries, eInfochips continues to fuel technological innovations in multiple verticals. The company offers complete product lifecycle solutions including hardware design, firmware, application software, testing, re-engineering, and manufacturing support. With an innovationcentric fabric, eInfochips has enabled companies to develop customized evaluation kits, reference designs and next-generation, fully featured products on leading platforms. Email security@arrow.com Online arrow.com/iot/iot-security ©2020 Arrow Electronics, Inc. Arrow and the Arrow logo are registered trademarks of Arrow Electronics, Inc. All other product names and logos are trademarks of their respective manufacturers. 11_10/20