Publicado el — Deja un comentario

AWS Elastic Beanstalk now supports Python 3.13 on Amazon Linux 2023

AWS Elastic Beanstalk now enables customers to build and deploy Python 3.13 applications on Amazon Linux 2023 (AL2023) platform. This latest platform support allows developers to leverage the newest features and improvements in Python while taking advantage of the enhanced security and performance of AL2023.

AWS Elastic Beanstalk is a service that provides the ability to deploy and manage applications in AWS without worrying about the infrastructure that runs those applications. Python 3.13 on AL2023 delivers enhanced interactive interpreter capabilities, improved error messages, and important security and API improvements. Developers can create Elastic Beanstalk environments running Python 3.13 on AL2023 through the Elastic Beanstalk Console, CLI, or API.

This platform is available in all commercial AWS Regions where Elastic Beanstalk is available, including the AWS GovCloud (US) Regions. For a complete list of regions and service offerings, see AWS Regions.

To learn more about Python 3.13 on Amazon Linux 2023, see the AWS Elastic Beanstalk Developer guide. For additional information, visit the AWS Elastic Beanstalk product page.

 

​AWS Elastic Beanstalk now enables customers to build and deploy Python 3.13 applications on Amazon Linux 2023 (AL2023) platform. This latest platform support allows developers to leverage the newest features and improvements in Python while taking advantage of the enhanced security and performance of AL2023.
AWS Elastic Beanstalk is a service that provides the ability to deploy and manage applications in AWS without worrying about the infrastructure that runs those applications. Python 3.13 on AL2023 delivers enhanced interactive interpreter capabilities, improved error messages, and important security and API improvements. Developers can create Elastic Beanstalk environments running Python 3.13 on AL2023 through the Elastic Beanstalk Console, CLI, or API.
This platform is available in all commercial AWS Regions where Elastic Beanstalk is available, including the AWS GovCloud (US) Regions. For a complete list of regions and service offerings, see AWS Regions.
To learn more about Python 3.13 on Amazon Linux 2023, see the AWS Elastic Beanstalk Developer guide. For additional information, visit the AWS Elastic Beanstalk product page.  

Publicado el — Deja un comentario

AWS Elemental MediaTailor now supports bring your own ads (BYOA) via VAST responses

With AWS Elemental MediaTailor you can now bring your own pre-transcoded HLS and DASH packaged ads through VAST responses, enabling custom control over ad transcoding. This new capability allows ad decision servers to include HLS and DASH manifest URLs for pre-transcoded multi-bitrate ad streams directly in the VAST XML creative file attributes. MediaTailor will stitch the pre-transcoded ad creative into the manifest without dynamic transcoding.

Previously, MediaTailor could only dynamically transcode ads to match the content stream at insertion time. With Bring-Your-Own-Ads via VAST, you can now pre-transcode ads and provide the transcoded manifest URLs via VAST, enabling use cases like server-side overlay ads and instantly inserting new ad creatives.

Bring-Your-Own-Ads via VAST can be enabled at the configuration level in MediaTailor. The feature supports both HLS and DASH streaming protocols and is available now in all regions where MediaTailor is supported.

Please see the MediaTailor User Guide for further details.

Visit the AWS region table for a full list of AWS Regions where AWS Elemental MediaTailor is available. To learn more about MediaTailor, please visit the product page.

 

​With AWS Elemental MediaTailor you can now bring your own pre-transcoded HLS and DASH packaged ads through VAST responses, enabling custom control over ad transcoding. This new capability allows ad decision servers to include HLS and DASH manifest URLs for pre-transcoded multi-bitrate ad streams directly in the VAST XML creative file attributes. MediaTailor will stitch the pre-transcoded ad creative into the manifest without dynamic transcoding. Previously, MediaTailor could only dynamically transcode ads to match the content stream at insertion time. With Bring-Your-Own-Ads via VAST, you can now pre-transcode ads and provide the transcoded manifest URLs via VAST, enabling use cases like server-side overlay ads and instantly inserting new ad creatives. Bring-Your-Own-Ads via VAST can be enabled at the configuration level in MediaTailor. The feature supports both HLS and DASH streaming protocols and is available now in all regions where MediaTailor is supported. Please see the MediaTailor User Guide for further details. Visit the AWS region table for a full list of AWS Regions where AWS Elemental MediaTailor is available. To learn more about MediaTailor, please visit the product page.  

Publicado el — Deja un comentario

Amazon Q Developer Pro tier adds automated user onboarding emails

The Amazon Q Developer Pro tier now offers automated email notifications for newly subscribed users. When a new user is subscribed by an administrator, users will now automatically receive a welcome email within 24 hours containing important information to help them get started quickly and efficiently with their new subscription. This automation streamlines the onboarding process and saves administrators valuable time by eliminating the need for them to manually notify each new user.

In the welcome email, users will find guidance on accessing the Q Console chat and details on downloading and installing the Q Developer plugin in their Integrated Development Environment (IDE). The email includes their unique Start URL and AWS region for authentication. Additionally, it provides quick-start steps for using Q Developer in their IDE.

To learn more about this new feature and other Amazon Q Developer Pro tier subscription management features, visit the AWS Console.

 

​The Amazon Q Developer Pro tier now offers automated email notifications for newly subscribed users. When a new user is subscribed by an administrator, users will now automatically receive a welcome email within 24 hours containing important information to help them get started quickly and efficiently with their new subscription. This automation streamlines the onboarding process and saves administrators valuable time by eliminating the need for them to manually notify each new user. In the welcome email, users will find guidance on accessing the Q Console chat and details on downloading and installing the Q Developer plugin in their Integrated Development Environment (IDE). The email includes their unique Start URL and AWS region for authentication. Additionally, it provides quick-start steps for using Q Developer in their IDE. To learn more about this new feature and other Amazon Q Developer Pro tier subscription management features, visit the AWS Console.  

Publicado el — Deja un comentario

AWS Elastic Beanstalk now supports .NET 9 on Amazon Linux 2023

AWS Elastic Beanstalk now enables customers to build and deploy .NET 9 applications on Amazon Linux 2023 (AL2023) platform. This latest platform support allows developers to leverage the newest .NET features while benefiting from AL2023’s enhanced security and performance features.

AWS Elastic Beanstalk is a service that provides the ability to deploy and manage applications in AWS without worrying about the infrastructure that runs those applications. .NET 9 on AL2023 delivers enhanced garbage collection capabilities and significant performance improvements. Developers can create Elastic Beanstalk environments running .NET 9 on AL2023 through the Elastic Beanstalk Console, CLI, or API.

This platform is generally available in commercial regions where Elastic Beanstalk is available including the AWS GovCloud (US) Regions. For a complete list of regions and service offerings, see AWS Regions.

For more information about .NET 9 and Linux Platforms, see the Elastic Beanstalk developer guide. To learn more about Elastic Beanstalk, visit the Elastic Beanstalk product page.

 

​AWS Elastic Beanstalk now enables customers to build and deploy .NET 9 applications on Amazon Linux 2023 (AL2023) platform. This latest platform support allows developers to leverage the newest .NET features while benefiting from AL2023’s enhanced security and performance features.
AWS Elastic Beanstalk is a service that provides the ability to deploy and manage applications in AWS without worrying about the infrastructure that runs those applications. .NET 9 on AL2023 delivers enhanced garbage collection capabilities and significant performance improvements. Developers can create Elastic Beanstalk environments running .NET 9 on AL2023 through the Elastic Beanstalk Console, CLI, or API.
This platform is generally available in commercial regions where Elastic Beanstalk is available including the AWS GovCloud (US) Regions. For a complete list of regions and service offerings, see AWS Regions.
For more information about .NET 9 and Linux Platforms, see the Elastic Beanstalk developer guide. To learn more about Elastic Beanstalk, visit the Elastic Beanstalk product page.  

Publicado el — Deja un comentario

Amazon S3 Tables add schema definition support to the CreateTable API

Amazon S3 announces schema definition support for the CreateTable API to programmatically create tables with pre-defined columns. This enhancement simplifies table creation for data analytics applications, making it easier to get started and ingest data in S3 table buckets.

To use this feature, you can specify column names and their data types as new request headers in the CreateTable API to define a table’s schema in an S3 table bucket. You can also define a table’s schema when you create tables using the AWS CLI or the AWS SDK.

To create tables with a pre-defined schema, upgrade to the latest version of the AWS CLI and AWS SDKs. This support is available in all AWS Regions where S3 Tables is available. To learn more, visit the Amazon S3 Tables overview page and documentation.

 

​Amazon S3 announces schema definition support for the CreateTable API to programmatically create tables with pre-defined columns. This enhancement simplifies table creation for data analytics applications, making it easier to get started and ingest data in S3 table buckets. To use this feature, you can specify column names and their data types as new request headers in the CreateTable API to define a table’s schema in an S3 table bucket. You can also define a table’s schema when you create tables using the AWS CLI or the AWS SDK. To create tables with a pre-defined schema, upgrade to the latest version of the AWS CLI and AWS SDKs. This support is available in all AWS Regions where S3 Tables is available. To learn more, visit the Amazon S3 Tables overview page and documentation.  

Publicado el — Deja un comentario

Amazon S3 Tables now support 10,000 tables per table bucket

Amazon S3 Tables now support creating up to 10,000 tables in each S3 table bucket. With this higher quota, you can scale up to 100,000 tables across 10 table buckets within an AWS Region per AWS Account. The higher table quota is available by default on all table buckets at no additional cost.

S3 Tables deliver the first cloud object store with built-in Apache Iceberg support, and the easiest way to store tabular data at scale. You can use S3 Tables with AWS Analytics services through the preview integration with Amazon SageMaker Lakehouse, as well as Apache Iceberg-compatible open source engines like Apache Spark and Apache Flink.

S3 Tables support 10,000 tables in each S3 table bucket in all AWS Regions where S3 Tables is available. To learn more, visit the Amazon S3 Tables overview page and documentation.
 

 

​Amazon S3 Tables now support creating up to 10,000 tables in each S3 table bucket. With this higher quota, you can scale up to 100,000 tables across 10 table buckets within an AWS Region per AWS Account. The higher table quota is available by default on all table buckets at no additional cost. S3 Tables deliver the first cloud object store with built-in Apache Iceberg support, and the easiest way to store tabular data at scale. You can use S3 Tables with AWS Analytics services through the preview integration with Amazon SageMaker Lakehouse, as well as Apache Iceberg-compatible open source engines like Apache Spark and Apache Flink. S3 Tables support 10,000 tables in each S3 table bucket in all AWS Regions where S3 Tables is available. To learn more, visit the Amazon S3 Tables overview page and documentation.    

Publicado el — Deja un comentario

Amazon Lex expands Assisted Slot Resolution regions and model access

Amazon Lex has expanded Assisted Slot Resolution to additional AWS regions and enhanced its capabilities through integration with newer Amazon Bedrock foundation models. Bot developers can now select from allowlisted foundation models in their account to enhance slot resolution capabilities, while maintaining the same simplified permission model through bot Service Linked Role updates.

When enabled, this feature helps chatbots better understand user responses during slot collection, activating during slot retries and fallback scenarios. The feature supports AMAZON.City, AMAZON.Country, AMAZON.Number, AMAZON.Date, AMAZON.AlphaNumeric (without regex), and AMAZON.PhoneNumber slot types, with the ability to enable improvements for individual slots during build time.

Assisted Slot Resolution is now available in Europe (Frankfurt, Ireland, London), Asia Pacific (Sydney, Singapore, Seoul, Tokyo), and Canada (Central) regions, in addition to US East (N. Virginia) and US West (Oregon). While there are no additional Amazon Lex charges for this feature, standard Amazon Bedrock pricing applies for foundation model usage.

To learn more about implementing these enhancements, please refer to our documentation on Assisted Slot Resolution. You can enable the feature through the Amazon Lex console or APIs.
 

 

​Amazon Lex has expanded Assisted Slot Resolution to additional AWS regions and enhanced its capabilities through integration with newer Amazon Bedrock foundation models. Bot developers can now select from allowlisted foundation models in their account to enhance slot resolution capabilities, while maintaining the same simplified permission model through bot Service Linked Role updates. When enabled, this feature helps chatbots better understand user responses during slot collection, activating during slot retries and fallback scenarios. The feature supports AMAZON.City, AMAZON.Country, AMAZON.Number, AMAZON.Date, AMAZON.AlphaNumeric (without regex), and AMAZON.PhoneNumber slot types, with the ability to enable improvements for individual slots during build time. Assisted Slot Resolution is now available in Europe (Frankfurt, Ireland, London), Asia Pacific (Sydney, Singapore, Seoul, Tokyo), and Canada (Central) regions, in addition to US East (N. Virginia) and US West (Oregon). While there are no additional Amazon Lex charges for this feature, standard Amazon Bedrock pricing applies for foundation model usage. To learn more about implementing these enhancements, please refer to our documentation on Assisted Slot Resolution. You can enable the feature through the Amazon Lex console or APIs.    

Publicado el — Deja un comentario

Amazon CloudWatch Synthetics adds IPv6 support

CloudWatch Synthetics now allows canaries running in a VPC to make outbound requests to IPv6 endpoints allowing monitoring of IPv6-only and dual stack enabled endpoints over IPv6. You can also access CloudWatch Synthetics APIs over both IPv4 and IPv6 through new dual stack compatible regional endpoints. Additionally, PrivateLink access to Synthetics within VPCs is now available over IPv6 connections.

Using CloudWatch Synthetics, you can now monitor the availability and performance of websites or microservices accessible via IPv6 endpoints ensuring that end users can use the applications seamlessly irrespective of their network protocol. You can create IPv6 enabled canaries in your VPC using the CLI, CDK, CloudFormation, or the AWS console, and update existing VPC canaries to support dual stack connectivity without making any script changes. You can monitor endpoints external to your VPC by giving the canary internet access and configuring the VPC subnets appropriately. Now you can manage Synthetics resources in environments with IPv6-only networking policies, or access Synthetics APIs via IPv6 without traffic traversing the internet using PrivateLink helping meet security and regulatory requirements.

IPv6 support for Synthetics is available in all commercial regions where CloudWatch Synthetics is present at no additional cost to the users.

To learn how to configure a IPv6 canary in a VPC see documentation, or click here to find dual-stack API management endpoints for Synthetics. See user guide and One Observability Workshop to get started with CloudWatch Synthetics.

 

​CloudWatch Synthetics now allows canaries running in a VPC to make outbound requests to IPv6 endpoints allowing monitoring of IPv6-only and dual stack enabled endpoints over IPv6. You can also access CloudWatch Synthetics APIs over both IPv4 and IPv6 through new dual stack compatible regional endpoints. Additionally, PrivateLink access to Synthetics within VPCs is now available over IPv6 connections. Using CloudWatch Synthetics, you can now monitor the availability and performance of websites or microservices accessible via IPv6 endpoints ensuring that end users can use the applications seamlessly irrespective of their network protocol. You can create IPv6 enabled canaries in your VPC using the CLI, CDK, CloudFormation, or the AWS console, and update existing VPC canaries to support dual stack connectivity without making any script changes. You can monitor endpoints external to your VPC by giving the canary internet access and configuring the VPC subnets appropriately. Now you can manage Synthetics resources in environments with IPv6-only networking policies, or access Synthetics APIs via IPv6 without traffic traversing the internet using PrivateLink helping meet security and regulatory requirements. IPv6 support for Synthetics is available in all commercial regions where CloudWatch Synthetics is present at no additional cost to the users. To learn how to configure a IPv6 canary in a VPC see documentation, or click here to find dual-stack API management endpoints for Synthetics. See user guide and One Observability Workshop to get started with CloudWatch Synthetics.  

Publicado el — Deja un comentario

Amazon SageMaker Unified Studio now in preview in seven additional Regions

Amazon SageMaker Unified Studio is now available in preview in seven additional AWS Regions: Asia Pacific (Seoul, Singapore, and Sydney), Europe (Frankfurt and London), South America (São Paulo), and Canada (Central).

Amazon SageMaker Unified Studio (preview) is an integrated data and AI development environment that enables collaboration and helps teams build data products faster. It brings together familiar tools from AWS analytics and AI/ML services for data processing, SQL analytics, machine learning model development, and generative AI application development into a single experience. SageMaker Unified Studio provides unified data access through Amazon SageMaker Lakehouse, and enhanced governance features are built in to help you meet enterprise security requirements. With the availability of new Regions, customers who have data sovereignty and low latency requirements can now use SageMaker Unified Studio while keeping their data and workloads closer to their primary operational Regions.

For more information on AWS Regions where SageMaker Unified Studio is available in preview, see Supported Regions.

You can create an Amazon SageMaker Unified Studio domain by visiting the Amazon SageMaker console. To get started, see the following resources:

 

​Amazon SageMaker Unified Studio is now available in preview in seven additional AWS Regions: Asia Pacific (Seoul, Singapore, and Sydney), Europe (Frankfurt and London), South America (São Paulo), and Canada (Central). Amazon SageMaker Unified Studio (preview) is an integrated data and AI development environment that enables collaboration and helps teams build data products faster. It brings together familiar tools from AWS analytics and AI/ML services for data processing, SQL analytics, machine learning model development, and generative AI application development into a single experience. SageMaker Unified Studio provides unified data access through Amazon SageMaker Lakehouse, and enhanced governance features are built in to help you meet enterprise security requirements. With the availability of new Regions, customers who have data sovereignty and low latency requirements can now use SageMaker Unified Studio while keeping their data and workloads closer to their primary operational Regions. For more information on AWS Regions where SageMaker Unified Studio is available in preview, see Supported Regions. You can create an Amazon SageMaker Unified Studio domain by visiting the Amazon SageMaker console. To get started, see the following resources:

SageMaker overview
SageMaker documentation
SageMaker in the AWS Management Console  

Publicado el — Deja un comentario

Descripción del procesador de seguridad de Microsoft Pluton  

enero 30, 2025

Descripción del procesador de seguridad de Microsoft Pluton  

Log Microsoft square

Por: Nazmus Sakib, director principal de producto.

A principios de este año, anunciamos que el procesador de seguridad Microsoft Pluton estará habilitado de forma predeterminada en todos los Copilot + PC para empresas. Con los nuevos dispositivos Pluton fabricados por nuestro rico ecosistema de socios de PC, nos gustaría aprovechar esta oportunidad para profundizar en esta tecnología fundamental y en cómo seguirá evolucionando.  

¿Qué es Pluton?  

El procesador de seguridad Microsoft Pluton (Pluton) es una base de hardware segura, flexible y actualizable para Windows 11. Cuando Microsoft anunció inicialmente Pluton en 2020 junto con nuestros socios de silicio, describimos los beneficios de seguridad y las protecciones que Pluton puede aportar a los dispositivos. Desde entonces, hemos estado trabajando con nuestros socios de silicio y dispositivos para ampliar la presencia de Pluton en el mercado de PC. El procesador de seguridad Pluton es un ejemplo de los compromisos de la Iniciativa de Futuro Seguro (SFI) de Microsoft en acción, al hacer que Windows sea aún más seguro por diseño, de forma predeterminada y en funcionamiento.  

Al operar directamente en hardware dedicado en el sistema en chip (SoC) de la CPU, Pluton ayuda a proporcionar protección adicional para activos confidenciales como credenciales y claves de cifrado. Pluton también recibe sus actualizaciones de firmware y funciones directamente de Microsoft, lo que simplifica la administración y brinda la protección continua más reciente para ayudar contra las amenazas actuales y futuras, al tiempo que se adhiere a las prácticas seguras de implementación y despliegue.  

Arquitectura de Pluton: una visión general  

Para que Pluton funcione, es necesario que se unan tres elementos: hardware, firmware y software. Estos elementos funcionan al unísono, como se muestra en este diagrama: 

Diagrama de los elementos que funcionan en Microsoft Pluton

Arquitectura para la seguridad hoy y en el futuro  

A medida que planeábamos la próxima ola de dispositivos Pluton, reconocimos dos entradas principales de cuando se concibió Pluton por primera vez:  

  • En 2019, los datos de investigación de seguridad de Microsoft mostraron que ~70% de las vulnerabilidades a las que Microsoft asigna un CVE eran problemas de seguridad de memoria. Anticipamos que la seguridad de la memoria sería aún más crítica para los clientes, dadas las líneas de tendencia esperadas del panorama de amenazas. El aviso de 2023 de la Agencia de Seguridad de Infraestructura y Ciberseguridad (CISA) del gobierno de EE. UU. ha destacado la necesidad urgente de seguridad de la memoria en los productos de software, lo que ha agregado enfoque y urgencia adicionales para abordar la amenaza. 
  • Los clientes esperaban usar sus dispositivos Windows durante más tiempo y, por lo tanto, querían que sus dispositivos se actualizaran de manera confiable durante la vida útil de su dispositivo. En línea con esta tendencia, Microsoft anunció en 2023 que los nuevos dispositivos Surface recibirían al menos seis años de actualizaciones de controladores y firmware a partir de la fecha de disponibilidad general, en lugar del mínimo anterior de cuatro años.[i] 

Estas observaciones nos llevaron a preguntarnos: ¿Qué deberíamos hacer para crear un procesador de seguridad que ayude a mantener a los clientes seguros el día que compraron un dispositivo y durante toda la vida útil del dispositivo?  

La capacidad de actualización había sido un objetivo fundamental desde el inicio de nuestro viaje a Pluton. Para ayudar a garantizar la resistencia de Plutón durante muchos años, era necesario construirlo sobre una plataforma segura para la memoria. Este enfoque permite que el procesador de seguridad, incluido con dispositivos como los Copilot+PC en 2024, se actualice y siga siendo más resistente frente al panorama de amenazas que cambia rápidamente, al tiempo que sigue teniendo un rendimiento en el futuro. Esto condujo a un cambio importante en la arquitectura de Pluton, donde dimos los primeros pasos sustanciales en el uso de Rust para el firmware del procesador de seguridad. 

Incorporación de Rust como base del firmware de nuestro procesador de seguridad Pluton con Tock OS  

Después de evaluar cuidadosamente múltiples enfoques, incluida la creación de una solución totalmente personalizada desde cero, decidimos usar Tock OS como base basada en Rust para Pluton. El kernel de Tock OS está completamente escrito en Rust y tiene una comunidad de código abierto pequeña pero activa.  

Tock OS forma la base común del firmware de Pluton, con soporte de hardware implementado para cada arquitectura con controladores y bibliotecas de interfaz de hardware (HIL). Las funciones orientadas al cliente, como el firmware del módulo de plataforma segura en las plataformas compatibles, se implementan como aplicaciones en modo de usuario de Tock sobre el kernel de Tock. 

Diagrama con el Firmware que compone a Pluton

Reconocemos que la creación de soluciones de seguridad es un deporte de equipo, y no queríamos usar Tock OS sin retribuir a esa comunidad. Ha sido increíble trabajar con la comunidad de Tock OS y nuestro equipo de Pluton ha agradecido la bienvenida que hemos sentido. Como parte de nuestro trabajo con Tock, nos complace destacar dos contribuciones recientes que el equipo de Pluton ha hecho: 

  • Para admitir Pluton en el hardware Intel® Partner Security Engine (IPSE), agregamos soporte para la arquitectura x86 a Tock.  

Estos cambios están disponibles públicamente y se han presentado para su revisión y futura inclusión en Tock: Port Kernel to x86 Architecture por reynoldsbd · Solicitud de incorporación de cambios #4171 · tock/tock (github.com).  

Copilot+ PCs con procesadores AMD Ryzen™ AI e Intel® Core™ Ultra (Serie 2) son las primeras plataformas Pluton que se lanzarán con nuestro nuevo núcleo basado en Rust. Apreciamos enormemente la asociación con AMD e Intel mientras colaboramos en este esfuerzo pionero. 

Hardware robusto diseñado para reducir la superficie de ataque  

En la capa de hardware, Pluton opera directamente en un procesador de seguridad de hardware dedicado que está integrado en el sistema en chip (SoC) más grande. Si bien cada proveedor de silicio de CPU implementa el hardware para el procesador de seguridad, la arquitectura es coherente para todas las PC con Windows 11. El procesador de seguridad de hardware tiene su propio núcleo de microcontrolador, que comienza desde su propia memoria de solo lectura (ROM) y luego carga el firmware de Pluton de integridad verificada en una memoria estática de acceso aleatorio (SRAM) dedicada y lo ejecuta.  

Un punto clave del diseño es aislar el silicio del procesador de seguridad Pluton de la unidad central de procesamiento (CPU) del SoC, los núcleos y otro hardware. Este enfoque se adoptó para hacer frente a los ataques de hardware que han salido a la luz en los últimos años y para reducir la superficie de ataque de las operaciones criptográficas y de seguridad críticas. Esto implica diferentes compensaciones entre rendimiento y seguridad de lo que se requiere para la CPU principal. Por ejemplo, cualquier ataque de canal lateral basado en caché dirigido a la memoria dinámica de acceso aleatorio (DRAM) del sistema principal no puede extraer información de la SRAM de Pluton. Los núcleos principales de la CPU solo pueden comunicarse con Pluton a través de una interfaz de hardware reforzada de seguridad dedicada, lo que reduce la superficie de ataque en Pluton.  

Además de un microcontrolador dedicado, ROM y SRAM, Pluton tiene su propio hardware centrado en la seguridad, por ejemplo, un generador de números aleatorios (RNG), aceleradores para algoritmos criptográficos como hashing (SHA-2), cifrado simétrico (AES), cifrado asimétrico (RSA y ECC) y otros. Esto no solo ayuda a garantizar que las operaciones sensibles a la seguridad, como la creación y el uso de claves criptográficas, se realicen dentro de los límites del hardware de Pluton y no puedan ser accedidas o interferidas por la CPU principal, sino que también ayuda a ofrecer un rendimiento óptimo para estas operaciones.  

El diseño de hardware de Pluton está destinado a complementar las capacidades de seguridad de hardware y firmware existentes en el sistema más grande. Capacidades como el arranque medido UEFI, el inicio seguro de System Guard y la integridad de la memoria siguen ayudando a proporcionar la protección necesaria para la ejecución de código en los núcleos de la CPU. 

El procesador de seguridad Pluton no controla ni intercepta la ejecución de ningún código en los núcleos de la CPU; por ejemplo, Pluton no controla qué sistema operativo se ejecuta en la máquina. Pluton está sujeto a las restricciones de la Unidad de Gestión de Memoria de Entrada/Salida (IOMMU), al igual que otros dispositivos. Los PC de núcleo seguro habilitan  la protección DMA del kernel, que aplica el aislamiento para los dispositivos del sistema, incluido Pluton. El procesador de seguridad Pluton puede proteger material criptográfico como claves y mediciones, y realizar operaciones sobre la información almacenada aislada de cualquier código que se ejecute en los núcleos de la CPU. Esta propiedad lo hace ideal para el propósito principal de Pluton, ayudar a proteger los secretos criptográficos de los atacantes, lo que ayuda a garantizar, por ejemplo, que los datos del usuario sean propiedad del usuario o que su identidad en el sistema siga siendo suya.  

Además de los componentes comunes mencionados anteriormente que existen en todos los procesadores de seguridad de Pluton, Microsoft también trabaja con nuestros socios de silicio para integrar algunas de las tecnologías de seguridad de hardware más avanzadas en sus respectivos diseños de procesadores de seguridad de Pluton, de modo que esos socios puedan agregar capacidades de seguridad adicionales exclusivas de sus chips, como innovaciones en protección contra la inyección de errores y los ataques de canal lateral.  o para lograr la certificación de seguridad. Como resultado, la capa de hardware de Pluton continuará evolucionando con tecnología de vanguardia de la industria en general.  

  • La serie AMD Ryzen 6000 fue pionera en™ las capacidades de Pluton, y los clientes pueden obtener más información sobre el hardware gracias a su certificación FIPS 140-3 recientemente obtenida. Los Copilot+ PCs lanzados este año en la serie AMD Ryzen™ AI 300 también incluyen soporte para Pluton.  
  • Los Copilot+ PCs equipados con la serie Snapdragon® X están equipados con la unidad de procesamiento seguro (SPU) de Qualcomm®, que permite implementar la funcionalidad de Pluton como aplicaciones seguras que se ejecutan en un enclave de seguridad independiente y de alta seguridad. Obtenga más información sobre los procesadores Snapdragon.  

La renovación del firmware garantiza una fuerte protección y fiabilidad  

La capa de firmware de Pluton hace uso de la capa de hardware para ayudar a proporcionar la funcionalidad de seguridad de mayor nivel necesaria para varios escenarios por el sistema operativo, la plataforma de aplicaciones o el firmware del sistema.  

Al igual que con otros códigos críticos para la seguridad desarrollados por Microsoft, el firmware de Pluton sigue estrictas prácticas recomendadas de seguridad de firmware, como protecciones sólidas de integridad del código para ayudar a proteger contra la ejecución de código no autorizada y protección de reversión para evitar la carga de versiones antiguas y vulnerables del firmware.  

El firmware de Pluton que se ejecuta en el hardware de Pluton de un silicio en particular utiliza funciones de hardware avanzadas cuando están disponibles, lo que fortalece aún más el sistema contra los ataques. Por ejemplo, el firmware de Pluton utiliza cualquier hardware de protección de memoria disponible en la capa de hardware para proteger aún más la SRAM del firmware. Utiliza el almacenamiento de claves de hardware, si está disponible, para ayudar a proteger aún más las claves, de modo que el firmware comprometido no pueda extraer información de claves secretas. Si bien el firmware de Pluton puede aprovechar diferentes capacidades de hardware, mantiene una interfaz consistente con la capa de software para que el software que interactúa con Pluton no tenga que cambiar.  

Controladores, características del sistema operativo y aplicaciones de Pluton que se ejecutan en Windows 11  

La capa de software de Pluton consta del sistema operativo normal y la compatibilidad con controladores para el procesador de seguridad de Pluton y la funcionalidad asociada. El controlador de Pluton o el controlador del módulo de plataforma segura (TPM) nativo del sistema operativo Windows determina automáticamente cómo interactuar con una configuración específica de Pluton. La funcionalidad de Pluton se abstrae de las capas de software y aplicaciones superiores, y el marco subyacente aprovechará automáticamente Pluton cuando esté disponible. Nuestro objetivo es ayudar a crear flujos de trabajo y experiencias de seguridad de extremo a extremo que tengan los fundamentos más sólidos en torno a la confiabilidad y una capacidad de servicio integrada que facilite la mejora continua. 

Configuraciones de Pluton compatibles  

Para satisfacer las diversas necesidades del amplio ecosistema de Windows, hay una variedad de configuraciones entre las que los OEM de Windows pueden elegir para satisfacer las necesidades de los diferentes clientes:  

  • Pluton se puede utilizar como procesador de seguridad junto con un dispositivo TPM 2.0 discreto. Pluton puede proporcionar capacidades de seguridad basadas en hardware que pueden ayudar a reforzar las características de seguridad de Windows existentes y habilitar nuevas capacidades de seguridad en el hardware compatible con futuras actualizaciones. 
  • Pluton también se puede configurar como TPM 2.0 en sistemas compatibles. Windows 11 usa la funcionalidad TPM 2.0 en características como BitLocker y Windows Hello para proteger los materiales criptográficos que se usan para proteger los datos y las identidades de los usuarios. Pluton cumple con la especificación TPM 2.0 de Trusted Computing Group (TCG) y los OEM tienen la opción de usar Pluton como TPM para el sistema o exponer la interfaz de usuario en la configuración del BIOS en el dispositivo que permite al cliente elegir Pluton u otra opción de TPM si está presente para su dispositivo.  

Más información sobre las configuraciones y los detalles de hardware para SoC específicos y modelos de PC están disponibles en la documentación de los socios de silicio y/o OEM.  

Presentación del proveedor de almacenamiento de claves Pluton  

Nos comprometemos a agregar nuevas funcionalidades de software que amplíen las características de seguridad de Pluton, proporcionando la protección más reciente contra el panorama de amenazas en evolución. La primera adición será un proveedor de almacenamiento de claves (KSP) para Pluton que esté habilitado incluso si Pluton no es el TPM configurado. Esto hará que las capacidades de criptografía de Pluton estén disponibles para el sistema Windows y las aplicaciones que utilizan API que son familiares para los desarrolladores de Windows. Además de las propiedades de seguridad de Pluton, las aplicaciones que se integren con el hardware de seguridad se beneficiarán de un comportamiento más amigable de los desarrolladores en torno a cómo se administran las claves en diferentes escenarios, incluidos eventos relativamente poco comunes pero importantes como actualizaciones de firmware y restablecimiento de PC. Por ejemplo, no hay interfaces para eliminar claves inadvertidamente: operaciones como borrar claves tendrían que ser realizadas por la aplicación que administra las claves o por una acción del sistema que sea intuitiva para el usuario final y que los desarrolladores estén acostumbrados a tener en cuenta, como el restablecimiento de la PC. Los equipos de Microsoft Entra e Intune están integrando la protección de sus componentes de cliente con el KSP de Pluton. Las futuras actualizaciones de los Copilot+ PC habilitarán el Pluton KSP y la funcionalidad asociada en hardware compatible.  

Obtengan más información sobre la seguridad en Windows

El libro actualizado sobre seguridad en Windows está disponible para ayudarte a comprender cómo mantenerte protegido con Windows. Descubre más sobre Windows 11 y las Copilot+ PC. 

Para conocer más sobre las soluciones de seguridad de Microsoft, visita nuestro sitio web. Guarda en tus marcadores el blog de seguridad para mantenerte al día con la cobertura de nuestros expertos. Síguenos en LinkedIn (Microsoft Security) y X (@MSFTSecurity) para recibir las últimas noticias y actualizaciones sobre ciberseguridad. 

[i] La compatibilidad extendida con controladores y firmware se aplica a los dispositivos que estuvieron disponibles de manera general en 2021 y años posteriores. Consulta el ciclo de vida de controladores y firmware de Surface para dispositivos con Windows para más detalles. 

Sigan la conversación y encuentren mejores prácticas. Guarden en sus marcadores la Comunidad Técnica de Windows y síganos en X (@MSWindowsITPro) y LinkedIn. ¿Necesitan soporte? Visita Windows en Microsoft Q&A. 

The post Descripción del procesador de seguridad de Microsoft Pluton   appeared first on Source LATAM.

 

​The post Descripción del procesador de seguridad de Microsoft Pluton   appeared first on Source LATAM.