Secure chip design. Authorized security evaluation.

Since July 2009, ChipFans has researched how chips prove their identity and protect their keys. We design authentication and encryption chips, and we evaluate the security of chip-based systems, including authorized penetration testing. Every evaluation ends with a written report and a remediation plan, followed by a retest.

We test only systems you own or are authorized to have tested, within a scope agreed in advance, and only after the system owner has authorized the work in writing.

Illustration of a secure chip’s layout The corner of a chip drawn the way layout tools show a design, one color and fill pattern per layer. A seal ring with a cut corner runs along the die edge, with a row of bond pads inside it. In the core, a block of key storage cells sits beside rows of logic cells, and a shield mesh of two top-metal wires snakes back and forth over the whole core. Labels point to the shield mesh, the key storage and the seal ring. Shield mesh over the coreKey storageSeal ring
Layers
Illustration of a secure chip’s layout, not a ChipFans product drawing. Layout tools show each layer in its own color and fill pattern; switch layers on and off to see how a design is built up.

Two lines of work

ChipFans does two kinds of work, both grounded in its research: we design authentication and encryption chips, and we evaluate the security of chip-based systems.

Secure chip design

We research how a chip can prove that it is genuine, and design authentication and encryption chips on that basis. Each chip is designed so that its keys never leave it, and is evaluated against the attacks it is meant to resist.

  • Authentication scheme research
  • Authentication chip design
  • Encryption chip design

Security evaluation

We carry out security evaluations of chip-based systems, including authorized penetration testing, under the system owner’s written authorization and an agreed scope. You receive a written report and a remediation plan, and we retest once the fixes are in.

  • Written report of each finding
  • Remediation plan with fixes ranked by risk
  • Retest of the fixes

How an evaluation works

Authorization comes first. Nothing is tested until the system owner has authorized the work in writing and the scope is agreed.

  1. 1

    Written authorization

    The system owner authorizes the evaluation in writing. If you are commissioning the work for the owner, the owner signs the authorization.

  2. 2

    Scope and rules of engagement

    Together we agree on the targets, exclusions, test windows, safety limits and contacts, and record them in writing.

Authorized scope

  1. 3

    Evaluation

    We test the agreed targets hands-on, under the agreed rules, and nothing outside them.

  2. 4

    Report

    We write up each finding with its evidence, impact and severity.

  3. 5

    Remediation plan

    We rank the fixes by risk and agree on the plan with the system owner.

  4. 6

    Retest and close-out

    We retest the fixes. Then we return or destroy your samples, firmware and data.

Read how we work

Since July 2009

ChipFans was founded in July 2009 to research authentication schemes for chips. That research shapes both lines of work: the chips we design, and how we evaluate chip-based systems.

Read about ChipFans

Report a security issue

If you find a vulnerability in a chip we designed or on this website, or want to report misuse of ChipFans’ name or work, email our security contact. We will keep you informed as we work on a fix, and agree a disclosure date with you.

Security contact

Security team

security@chipfans.com

chipfans.com/.well-known/security.txt

Contact
mailto:security@chipfans.com
Expires
2027-04-10T00:00:00.000Z
Policy
https://chipfans.com/trust#disclosure
Canonical
https://chipfans.com/.well-known/security.txt
Preferred-Languages
en