Open And Secure Distributed Security Architecture
SiFive Shield is a comprehensive portfolio of hardware security technologies designed for RISC-V processors and SoCs.
Overview
SiFive Shield is a comprehensive portfolio of hardware security technologies designed for RISC-V processors and SoCs. Combining the RISC-V open standard with proprietary innovations, Shield delivers essential capabilities across memory protection, isolation, advanced cryptography, and secure debug. This scalable portfolio establishes the foundation for scalable and extensive security in embedded, automotive, and datacenter platforms.
Challenge
Modern SoCs face escalating threats, from memory corruption to complex DMA attacks and microarchitectural vulnerabilities. Highly virtualized systems require robust hardware isolation and secure memory management that protect data without bottlenecking overall system performance.
Solution
SiFive Shield unites complementary defenses into a single, cohesive architecture. The portfolio includes privilege-based isolation, Physical Memory Protection (PMP, ePMP, SPMP), WorldGuard, and IOMMU support. It also integrates cryptography, Control Flow Integrity, and secure microarchitectural enhancements for comprehensive hardware enforced protection.
Impact
This unified portfolio simplifies the development of secure RISC-V systems. You can accelerate time-to-market, enforce strict logical isolation, and build resilient products that meet stringent security standards while maintaining the flexibility of open standard compute.
The SiFive Shield platform provides a comprehensive, pre-validated security architecture designed to harden high performance processor IP against sophisticated physical and logical threats. Instead of relying on fragmented, bolt on security patches, Shield unifies defensive microarchitecture extensions with turnkey cryptographic accelerators and a robust root of trust. This cohesive approach coordinates defenses across every layer of the compute environment, effectively eliminating single points of failure. For system architects, this delivers scalable security compliance while significantly accelerating overall time to market.
Key features
- SiFive WorldGuard: Hardware system level isolation supporting multiple independent execution worlds.
- Hardware Cryptographic Accelerator: SCA resistant engine.
- Control Flow Integrity: Landing Pad and Shadow stack instructions that prevent ROP and JOP attacks.
- Secure Branch Predictor: Mitigates Spectre-like side channel vulnerabilities.
- Pointer Masking: Helps mitigate buffer overflow and use-after-free exploits.
- Fully Digital TRNG: High entropy generation evaluated against NIST SP 800-90B compliance standards.
- Vector Cryptographic Extensions: Accelerated encryption and secure hashing workloads (AES, SHA2, SM3, SM4).
- Multi-Layer Debug: Secure access control featuring public key based authentication protocols.
Block Diagram
Applications
- Data Center
- Automotive
- Edge AI
- IoT
- Embedded
Specifications
Identity
Files
Note: some files may require an NDA depending on provider policy.
Provider
Learn more about Root Of Trust IP core
Root of Trust: A Security Essential for Cyber Defense
Tailoring Root Of Trust Security Capabilities To Specific Customer Needs
Rambus CryptoManager Root of Trust Solutions Tailor Security Capabilities to Specific Customer Needs with New Three-Tier Architecture
Rambus RT-660 Root of Trust IP Achieves FIPS 140-3 Certification
Extending Security IP leadership with FIPS 140-2 CMVP Certification for Root of Trust IP
Frequently asked questions about Root of Trust IP cores
What is Open And Secure Distributed Security Architecture?
Open And Secure Distributed Security Architecture is a Root Of Trust IP core from Sifive, Inc. listed on Semi IP Hub.
How should engineers evaluate this Root Of Trust?
Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Root Of Trust IP.
Can this semiconductor IP be compared with similar products?
Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.