Vendor: CAST Category: Root Of Trust

GEON™ Secure Boot Hardware Engine

GEON-SBoot is an area-efficient, processor-agnostic hardware engine that protects SoC designs from booting with malicious or othe…

Overview

GEON-SBoot is an area-efficient, processor-agnostic hardware engine that protects SoC designs from booting with malicious or otherwise insecure code.

The security platform employs public-key cryptography (which stores no secret on-chip) to ensure that only unmodified firmware from a trusted source is used by the system. It also enables secure firmware updates over-the-air (OTA) and can prevent booting from revoked firmware versions. Optionally, GEON-SBoot can use symmetric encryption to protect the confidentiality of the firmware and prevent other devices from running firmware clones.

Designed for straightforward use in nearly any SoC, GEON-SBoot works with all modern architectures including RISC-V and ARM. It requires no software assistance from the host CPU, is independent of the memory types used, and uses standard interfaces. It further gives designers great flexibility in the boot control flow.

The isolated GEON-SBoot subsystem interfaces to the host system via three AMBA® ports: a subordinate AHB port for receiving the encrypted firmware, an AHB manager port for writing the authenticated, decrypted firmware to the system’s memory, and an APB subordinate port for receiving the security parameters. The security parameters (i.e., a hash of the public key and the symmetric key if used) are typically stored in immutable memory, constituting the root of trust. GEON-SBoot reports boot success or failure on its status register and via dedicated interrupt lines. It can optionally make its crypto accelerators available to the host system post-boot.

The GEON-SBoot core is production-proven and adheres to the industry’s best coding and verification practices to ensure trouble-free implementation in ASIC or FPGA technologies.

Key features

  • Protection Layers
    • Ensures integrity and authenticity of boot image
    • Prevents any firmware down-grade (anti-rollback)
    • Optionally protects confidentiality and prevents firmware cloning
    • Complete software and hardware isolation from the host SoC
  • Public-Key Authentication Benefits
    • No secret on die for resistance to physical and side-channel attacks and easy deployment
    • Over The Air updates
    • Immune to break-one break-all scenarios
  • Fast & Compact
    • Minimal boot time impact: typically from sub-ms to a few ms
    • From 50k gates and 8k to 11k bytes of memory
  • Cryptographic Algorithms
    • Asymmetric authentication
      • RSA signature verification with key lengths 2,048, 3,072, and 4,096 bits (default)
      • ECC signature verification with NIST-validated( i.e. P-224, P-256, P-384, & P-521) or custom curves (option)
    • SHA3-256/384/512 Hashing or SHA-244 (option)
    • Symmetric authenticated decryption with AES-GCM with key length of 128 or 256 bits (option)
  • Easy to Use and Integrate
    • AMBA AHB and APB interfaces
    • Autonomous & isolated operation requires no software assistance.
    • Protected firmware can be broken into fragments, each stored in different memory regions. Multi-stage boot support
    • Crypto acceleration engines can be made available to the system after boot
  • Reusable & Portable
    • Processor-Agnostic: works with any host processor(s) or SoC
    • Process-Independent RTL design
  • Deliverables
    • Verilog RTL source code or targeted FPGA netlist
    • Comprehensive Documentation
    • Software tool for signing and encrypting boot images

Block Diagram

Specifications

Identity

Part Number
GEON-SBoot
Vendor
CAST
Type
Silicon IP

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: USA

Learn more about Root Of Trust IP core

Ten Years in CiA, Over Two Decades of CAN IP Reliability

CAST marks a ten-year anniversary in the CiA organization with a look at the company's longer history of industry-leading soft IP cores—covering CAN 2.0, CAN FD, CAN XL, CANsec, and ISO 26262 certification—proven with over 200 CAN IP customers.

Firmware Compression for Lower Energy and Faster Boot in IoT Devices

The phrase “IoT” for Internet of Things has exploded to cover a wide range of different applications and diverse devices with very different requirements. Most observers, however, would agree that low energy consumption is a key element for IoT, as many of these devices must run on batteries or harvest energy from the environment.

Using a Versatile, Independent IP Platform for SoC Design

This paper shows how companies adopting an IP platform approach can maximize the benefits of their investment by choosing a flexible, versatile platform suitable for a variety of projects. Major points to consider are illustrated through one such platform, the PIP-AMBA from CAST

Frequently asked questions about Root of Trust IP cores

What is GEON™ Secure Boot Hardware Engine?

GEON™ Secure Boot Hardware Engine is a Root Of Trust IP core from CAST listed on Semi IP Hub.

How should engineers evaluate this Root Of Trust?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Root Of Trust IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP