Vendor: PUFsecurity Category: Root Of Trust

Hardware Root of Trust IP

Hardware root key generation and storage that never leaves the chip PUFrt includes a 1024-bit physical unclonable function (PUF) …

Overview

Hardware root key generation and storage that never leaves the chip

PUFrt includes a 1024-bit physical unclonable function (PUF) and a true random number generator (TRNG) complying with the NIST SP800- 90B/SP-800-22 standard specifications. These features aid in the encryption/decryption requirements of sensitive information and data, achieving a higher level of data security protection. Furthermore, an additional 8k-bit secure storage space with PUF is provided for the key or sensitive information injected by the customer, which makes the original security and NeoFuse OTP more resistant to physical attacks.

The rising risks from the IoT are limiting its potential. For perspective, it takes, on average, only five minutes for a deployed IoT device to receive its first attack. The answer is creating a collaborative security ecosystem, drawing from the safest Hardware, Software, and Operating System solutions. PUFrt can protect and connect this ecosystem at the hardware level using PUF-based encryption and authentication.

PUFrt’s Hardware Root of Trust is ushering in a new era of semiconductor security with its combination of secure Hard Macros and Digital RTL. PUFrt design includes a PUF-based 1024-bit identification code, Zero Touch key provisioning, intergrade entropy sources, secure OTP, and anti-tamper shell all in one unit. It can be integrated across a wide array of different architecture and support various operations, from lightweight hardware security key provisioning to fully functioning Crypto Coprocessors.

We lead the field in terms of platform availability, and through our parent company, eMemory, we draw from over 20 years of experience partnering with foundries and delivering high-quality IPs.

Key features

  • Process Availability
    • Scalable down to 3nm, and continuous development
    • Available across worldwide foundries
    • Security Features
    • Riscure certified
    • Resistant to physical attacks, including decapsulation, microscope imaging, probing, reverse engineering, etc.
  • PUF-based Secure Storage
    • Up to 128Kb OTP
    • Various memory maps configurations to fulfill different usage scenarios
    • Dummy insertion read based on entropy from TRNG
    • Scrambler based on PUF value securely stores keys, unique to each PUFrt
    • Stored values cannot be changed/deleted
  • Controller/Interface
    • APB or AHB System Bus Interface
    • APB or TCM Private Bus Interface
    • Secure OTP Wrapper (Factory test, user, RMA debug, Read/Write, Read-Only, and Non-accessible modes)
    • IEEE1687 JTAG testing interface
    • Optional XiP package available
    • Autoload interface for system calibration upon powering on to support product LFM, secure boot, secure debug, etc.
    • Memory Built-In Self Repair/Test Data Register/Secure Debug access through external Test Access Port
  • NIST SP800-90C Compliant TRNG
    • Pre-harden and calibration free
    • Ultra-fast initialization and stabilization (<100us)
    • High-speed throughput (>160 Mbits/sec)
    • Ultra-low power
    • Compliant with NIST SP800-22 and NIST SP800-90B with IID/restart test
    • NIST SP800-90A DRBG for >1Gbps random number generation available as an optional accessory
  • PUF-based Unique ID
    • With ideal minimum entropy of 1
    • Unpredictable randomness and uniqueness for UID with 50% Hamming weight and Hamming distance
    • On-demand keys for on-chip secret and off-chip ID generation
    • Optimal reliability with lifetime zero Bit Error-Rate (BER)
    • Robustness of working under different circumstances (Temp: -40~175°C)

Block Diagram

Benefits

  • Built-in standard APB controller with privilege control to create secure/non-secure separation. Additionally, interface customization is available for different design requirements.
  • Four 256-bit hardware PUF chip fingerprints, include a self-health check that can be used as a unique identification(UID) or a root key(seed).
  • High-quality true random number generator (TRNG)
  • 8k-bit mass production OTP with built-in instant hardware encryption (customization available)
  • Comprehensive anti-tamper designs in both Digital RTL and Hard Macros
  • Autoload: Automatically send trim parameters from OTP upon power-up.
  • Secure Boot: Ensure the device only boots up with the authenticated software.
  • Secure Debug: Ensure robust protection against potential backdoor attacks through the Debug Access Port (DAP)

Applications

  • Secure OTP to safely store sensitive data such as keys and boot code
  • Key provisioning that enables simultaneous multi-chip key provisioning for cost reduction
  • Entropy source for cryptographic engines and secure operations

What’s Included?

  • Datasheet
  • Release Notes
  • Integration Guidelines
  • Timing .lib File
  • LEF
  • GDS Phantom File
  • Verilog HDL File (Behavior Model)
  • Verilog HDL File (FPGA)
  • Application Note
  • Reference Scripts
  • Hard Macro Release Note
  • Test Methodology
  • Testbench

Specifications

Identity

Part Number
PUFrt
Vendor
PUFsecurity
Type
Silicon IP

Videos

PUFrt - Solving Chip Security's Weakest Link with PUF-based Root of Trust
When it comes to chip security, designers often turn to crypto subsystem solutions like ARM Crypto Cell 312. The remained obstacle, however, is how to generate and safely store the root key for the system. The dual APB PUFrt is the exact missing piece for the puzzle. With the inborn chip fingerprint from PUF that acts as a secret key to encrypt anything stored, the equipped anti-tamper shell makes it more resilient against potential attacks. With its well-planned architecture, PUFrt can be easily dropped in to replace eFuse while saving engineering effort as the controller is included. The combined solution not only completes secure boundary for IC but also maximizes the effectiveness of CC312 for the entire SoC’s performance.

Files

Note: some files may require an NDA depending on provider policy.

Provider

HQ: Taiwan

Learn more about Root Of Trust IP core

Why Hardware Root of Trust Needs Anti-Tampering Design

The hardware root of trust (HRoT) provides the trust base (root key), hardware identifier (UID), hardware unique key (HUK), and entropy required for the secure operation of the entire chip and therefore is often the focus of hacker attacks. If the design can’t effectively resist attacks, hackers can easily obtain the secrets of the entire chip. Attackers can use the secrets to crack identity authentication and data encryption and steal product design know-how, causing application security problems.

PUF based Root of Trust PUFrt for High-Security AI Application

This article will discuss how to strengthen the security of AI systems from the structure of the AI hardware device, to the security requirements, solutions, and etc. To do this, we will use PUFsecurity’s hardware root of trust module, PUFrt, as an example to help readers understand how combining AI application architecture and physical unclonable function (PUF) can benefit hardware security technology.

Solving Chip Security's Weakest Link

With the invention of Physical Unclonable Functions (PUF), we can now create a unique, inborn, unclonable key at the hardware level. The natural follow-up question to this is, “but how do we protect this key?” It is like storing your key to secrets in a drawer, a surefire way to break the secure boundary and create vulnerabilities.

Build Trust in Silicon: A Myth or a Reality?

Currently, there is a strong belief among the cyber security experts that hardware security is imperative since it is more efficient, effective, reliable and tamper-resistant than software security. As a matter of fact, providing trusted execution environment (TEE) and embedding a hardware root of trust (HRoT) as the anchor are necessary to provide a firm foundation for electronic systems security.

The Challenge of Automotive Hardware Security Deployment

A complete reinvention of the automotive industry is currently underway. Autonomous driving, connected vehicles, and the electrification of the powertrain all represent a once-in-a-generation shift in the manufacturing process.

The Four Angles of Examining PUF

The security of AIoT devices has become increasingly important. In order to ensure that the system’s security functions are working effectively and protecting every node and edge device from information security risks, it is important to generate a unique root of trust in the security system rooted in the chip.

Frequently asked questions about Root of Trust IP cores

What is Hardware Root of Trust IP?

Hardware Root of Trust IP is a Root Of Trust IP core from PUFsecurity listed on Semi IP Hub.

How should engineers evaluate this Root Of Trust?

Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Root Of Trust IP.

Can this semiconductor IP be compared with similar products?

Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.

×
Semiconductor IP