Securing Data Center and AI Infrastructure with CryptoManager™ Root of Trust for Use with the Caliptra™ Specification

The unprecedented growth of data centers and AI infrastructure brings with it a host of challenges. To address performance and power requirements, architectures continue to move to greater heterogeneity where purpose-built AI accelerators, SmartNICs and XPUs complement CPUs to tackle increasingly complex workloads. From a security perspective, this increasing complexity creates a larger attack surface, while at the same time, the value of the data and AI assets continue to rise. As a result, the challenge of establishing system-wide trust as a foundation for protection has never been greater.

At the heart of this challenge is the need for a hardware Root of Trust. A Root of Trust provides the foundational security services required to establish device identity, verify code integrity, protect cryptographic assets and support attestation throughout the lifetime of a device. In AI and cloud infrastructure, where valuable models, proprietary data and critical workloads are constantly in motion, a trusted foundation has become essential.

This need for a common security foundation is one of the reasons why the Caliptra™ project is gaining industry momentum. Developed through collaboration among leading cloud and semiconductor companies, Caliptra provides an open-source silicon Root of Trust architecture designed specifically for data center-class devices. It helps create a common framework for device identity, measured boot and attestation while enabling greater consistency across hardware platforms.

However, adopting Caliptra is only the beginning of the journey.

The Challenge of Moving from Adoption to Deployment

An open-source Root of Trust provides a valuable starting point, but production deployment introduces a new set of requirements. Silicon vendors must connect the Root of Trust to the broader SoC architecture, integrate it into secure boot and attestation flows, manage provisioning and lifecycle requirements, and support the cryptographic services needed by the rest of the platform.

Organizations pursuing deployment quickly discover that a production-ready security architecture must address issues beyond the scope of a baseline implementation. Questions arise around certification readiness, secure provisioning, attack resistance, software integration, long-term maintenance and support. Many products also require greater cryptographic capabilities, including agile support and regional cryptographic standards.

Bridging the Gap with CryptoManager Root of Trust for Use with the Caliptra Specification

To help semiconductor companies move from Caliptra adoption to production deployment, Rambus is introducing use with the Caliptra specification.

The CryptoManager solution is designed to work alongside the Caliptra core. Caliptra can provide the ecosystem-aligned foundation for device identity, measurement and attestation, while the Rambus solution extends trust across the broader SoC and delivers the capabilities required for commercial deployment, including support from Rambus.

This approach is particularly important for organizations seeking alignment with the Caliptra ecosystem and who require Caliptra trademark compliance. The CryptoManager solution preserves the role of an unmodified Caliptra implementation, including trademark compliance, while adding the infrastructure necessary to transform that foundation into a complete security architecture.

The solution provides a secure execution environment, protected key storage, platform-level security orchestration, dedicated Caliptra drivers and system applications, as well as the integration framework needed to simplify deployment. Together, these capabilities enable customers to extend trust throughout the platform rather than limiting it to the boundaries of the Caliptra subsystem.

For organizations targeting frameworks such as FIPS 140-3, PSA Certified or SESIP, the CryptoManager Root of Trust provides a structured foundation that helps simplify certification-oriented development efforts.


Explore Rambus IP:


Accelerating Time to Market

Beyond security, development efficiency is becoming a critical competitive advantage.

Building a complete Root of Trust architecture from the ground up requires substantial engineering investment. Development teams must create firmware, APIs, drivers, management applications, integration frameworks and documentation before they can begin focusing on product differentiation.

CryptoManager Root of Trust for use with the Caliptra specification reduces this burden by delivering a comprehensive hardware and software integration framework that includes secure firmware, device drivers, APIs, system applications and supporting documentation. Optional integration, maintenance and certification support services provide an additional layer of expertise to help customers accelerate deployment and reduce risk.

The result is a solution that allows engineering teams to spend less time building security infrastructure and more time creating innovative products.

For more information on the CryptoManager Root of Trust for use with the Caliptra specification, please check here.

×
Semiconductor IP