Secure chip design. Authorized security evaluation.
Since July 2009, ChipFans has researched how chips prove their identity and protect their keys. We design authentication and encryption chips, and we evaluate the security of chip-based systems, including authorized penetration testing. Every evaluation ends with a written report and a remediation plan, followed by a retest.
We test only systems you own or are authorized to have tested, within a scope agreed in advance, and only after the system owner has authorized the work in writing.
Two lines of work
ChipFans does two kinds of work, both grounded in its research: we design authentication and encryption chips, and we evaluate the security of chip-based systems.
Secure chip design
We research how a chip can prove that it is genuine, and design authentication and encryption chips on that basis. Each chip is designed so that its keys never leave it, and is evaluated against the attacks it is meant to resist.
- Authentication scheme research
- Authentication chip design
- Encryption chip design
Security evaluation
We carry out security evaluations of chip-based systems, including authorized penetration testing, under the system owner’s written authorization and an agreed scope. You receive a written report and a remediation plan, and we retest once the fixes are in.
- Written report of each finding
- Remediation plan with fixes ranked by risk
- Retest of the fixes
How an evaluation works
Authorization comes first. Nothing is tested until the system owner has authorized the work in writing and the scope is agreed.
- 1
Written authorization
The system owner authorizes the evaluation in writing. If you are commissioning the work for the owner, the owner signs the authorization.
- 2
Scope and rules of engagement
Together we agree on the targets, exclusions, test windows, safety limits and contacts, and record them in writing.
Authorized scope
- 3
Evaluation
We test the agreed targets hands-on, under the agreed rules, and nothing outside them.
- 4
Report
We write up each finding with its evidence, impact and severity.
- 5
Remediation plan
We rank the fixes by risk and agree on the plan with the system owner.
- 6
Retest and close-out
We retest the fixes. Then we return or destroy your samples, firmware and data.
Since July 2009
ChipFans was founded in July 2009 to research authentication schemes for chips. That research shapes both lines of work: the chips we design, and how we evaluate chip-based systems.
Report a security issue
If you find a vulnerability in a chip we designed or on this website, or want to report misuse of ChipFans’ name or work, email our security contact. We will keep you informed as we work on a fix, and agree a disclosure date with you.
chipfans.com/.well-known/security.txt
- Contact
- mailto:security@chipfans.com
- Expires
- 2027-04-10T
00:00:00.000Z - Policy
- https://chipfans.com/
trust #disclosure - Canonical
- https://chipfans.com/
.well-known/ security.txt - Preferred-Languages
- en